<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" href="static/style.xsl"?><OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd"><responseDate>2026-09-19T19:10:40Z</responseDate><request verb="GetRecord" identifier="oai:dspace.mit.edu:1721.1/145226" metadataPrefix="dim">https://dspace.mit.edu/server/oai/request</request><GetRecord><record><header><identifier>oai:dspace.mit.edu:1721.1/145226</identifier><datestamp>2025-10-30T15:50:01Z</datestamp><setSpec>com_1721.1_7582</setSpec><setSpec>com_1721.1_7581</setSpec><setSpec>col_1721.1_131023</setSpec></header><metadata><dim:dim xmlns:dim="http://www.dspace.org/xmlns/dspace/dim" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:doc="http://www.lyncode.com/xoai" xsi:schemaLocation="http://www.dspace.org/xmlns/dspace/dim http://www.dspace.org/schema/dim.xsd">
   <dim:field mdschema="dc" element="contributor" qualifier="advisor">Abel Sanchez.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="author" lang="en_US">Dowmon, Nicholas H.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">Massachusetts Institute of Technology. Engineering Systems Division.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="other" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">Massachusetts Institute of Technology. Engineering Systems Division</dim:field>
   <dim:field mdschema="dc" element="contributor" qualifier="department" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="accessioned">2022-08-31T16:29:17Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="available">2022-08-31T16:29:17Z</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="copyright" lang="en_US">2020</dim:field>
   <dim:field mdschema="dc" element="date" qualifier="issued" lang="en_US">2020</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="uri">https://hdl.handle.net/1721.1/145226</dim:field>
   <dim:field mdschema="dc" element="identifier" qualifier="oclc" lang="en_US">1341991441</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Thesis: S.M. in Engineering and Management, Massachusetts Institute of Technology, Engineering Systems Division, System Design and Management Program, 2020</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Cataloged from PDF version of thesis.</dim:field>
   <dim:field mdschema="dc" element="description" lang="en_US">Includes bibliographical references (pages 89-92).</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="abstract" lang="en_US">The goal of this research is to develop a framework for detecting anomalies in network traffic data on highly complex computer networks. In this research, I present the Ensemble Outlier Detection System, a new framework for detecting anomalies in multidimensional network traffic data. The system meets six design requirements which ensure that the system can meet the needs of the sponsor organization's cybersecurity teams both now and in the future. In particular, this system improves on many existing anomaly detection systems by maintaining scalability for extremely large computer networks and resiliency to non-stationary data, re-establishing its own baselines as the network changes over time. I also present the Explorer tool, designed for cybersecurity analysts to interpret the cause of high anomaly scores on certain data points and to annotate each data point atomically. I ensure scalability by treating all fields in a data point as independent of one another. Preliminary results suggest that this treatment will not affect system performance, as many anomalous data points exhibit multiple anom-alous -fields-at- a time, increasing the outlier predictions for the data point using recursive aggregation. The system successfully detects and presents interpretations of various anomalies in network traffic from the sponsoring institution's dataset, and achieves performance values which can detect real-time anomalies in enterprise computer networks.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="statementofresponsibility" lang="en_US">by Nicholas Dowmon.</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="degree" lang="en_US">S.M. in Engineering and Management</dim:field>
   <dim:field mdschema="dc" element="description" qualifier="collection" lang="en_US">S.M. in Engineering and Management Massachusetts Institute of Technology, Engineering Systems Division, System Design and Management Program</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="extent" lang="en_US">92 pages</dim:field>
   <dim:field mdschema="dc" element="language" qualifier="iso" lang="en_US">eng</dim:field>
   <dim:field mdschema="dc" element="publisher" lang="en_US">Massachusetts Institute of Technology</dim:field>
   <dim:field mdschema="dc" element="rights" lang="en_US">MIT theses may be protected by copyright. Please reuse MIT thesis content according to the MIT Libraries Permissions Policy, which is available through the URL provided.</dim:field>
   <dim:field mdschema="dc" element="rights" qualifier="uri" lang="en_US">http://dspace.mit.edu/handle/1721.1/7582</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">Engineering Systems Division.</dim:field>
   <dim:field mdschema="dc" element="subject" lang="en_US">System Design and Management Program.</dim:field>
   <dim:field mdschema="dc" element="title" lang="en_US">A generic framework for detecting interpretable real-time anomalies in network traffic data</dim:field>
   <dim:field mdschema="dc" element="type" lang="en_US">Thesis</dim:field>
   <dim:field mdschema="dc" element="format" qualifier="mimetype">application/pdf</dim:field>
   <dim:field mdschema="dspace" element="imported" lang="en_US">2022-08-31T16:29:17Z</dim:field>
   <dim:field mdschema="dspace" element="entity" qualifier="type">Publication</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="degree" lang="en_US">Master</dim:field>
   <dim:field mdschema="mit" element="thesis" qualifier="department" lang="en_US">Sloan</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="others" element="access-status">unknown</dim:field>
   <dim:field mdschema="cerif" element="openaire" authority="" confidence="-1">&lt;Publication xmlns="https://www.openaire.eu/cerif-profile/1.1/" id="f5aca95d-bc26-4035-be34-c20a657e1a52">
	&lt;Type xmlns="https://www.openaire.eu/cerif-profile/vocab/COAR_Publication_Types">http://purl.org/coar/resource_type/c_1843&lt;/Type>
	&lt;Language>eng&lt;/Language>
   	&lt;Title>A generic framework for detecting interpretable real-time anomalies in network traffic data&lt;/Title>
   	&lt;PublishedIn>
    	&lt;Publication>
      	&lt;/Publication>
   	&lt;/PublishedIn>
   	&lt;PublicationDate>2020&lt;/PublicationDate>
   	&lt;Authors>
      	&lt;Author>
        	&lt;DisplayName>Dowmon, Nicholas H.&lt;/DisplayName>
         	&lt;Affiliation>
         		&lt;OrgUnit>
         		&lt;/OrgUnit>
         	&lt;/Affiliation>
      	&lt;/Author>
	&lt;/Authors>
   	&lt;Editors>
	&lt;/Editors>
    &lt;Publishers>
        &lt;Publisher>
            &lt;DisplayName>Massachusetts Institute of Technology&lt;/DisplayName>
            &lt;OrgUnit />
        &lt;/Publisher>
    &lt;/Publishers>
    &lt;License>http://dspace.mit.edu/handle/1721.1/7582&lt;/License>
    &lt;Keyword>Engineering Systems Division.&lt;/Keyword>
    &lt;Keyword>System Design and Management Program.&lt;/Keyword>
   	&lt;Abstract>The goal of this research is to develop a framework for detecting anomalies in network traffic data on highly complex computer networks. In this research, I present the Ensemble Outlier Detection System, a new framework for detecting anomalies in multidimensional network traffic data. The system meets six design requirements which ensure that the system can meet the needs of the sponsor organization&amp;apos;s cybersecurity teams both now and in the future. In particular, this system improves on many existing anomaly detection systems by maintaining scalability for extremely large computer networks and resiliency to non-stationary data, re-establishing its own baselines as the network changes over time. I also present the Explorer tool, designed for cybersecurity analysts to interpret the cause of high anomaly scores on certain data points and to annotate each data point atomically. I ensure scalability by treating all fields in a data point as independent of one another. Preliminary results suggest that this treatment will not affect system performance, as many anomalous data points exhibit multiple anom-alous -fields-at- a time, increasing the outlier predictions for the data point using recursive aggregation. The system successfully detects and presents interpretations of various anomalies in network traffic from the sponsoring institution&amp;apos;s dataset, and achieves performance values which can detect real-time anomalies in enterprise computer networks.&lt;/Abstract>
	&lt;Access xmlns="http://purl.org/coar/access_right" 
    >
    &lt;/Access>
&lt;/Publication>
</dim:field>
</dim:dim>
</metadata></record></GetRecord></OAI-PMH>