Tenko: A Zero Trust Inspired Framework for Real-Time Network Defense via Intelligent Thresholding and Node-Level Anomaly Scoring

dc.contributor.authorBhola, Sahilen
dc.contributor.committeechairBurger, Eric Williamen
dc.contributor.committeechairCameron, Melissaen
dc.contributor.committeememberJi, Boen
dc.contributor.departmentComputer Science and#38; Applicationsen
dc.date.accessioned2025-06-14T08:00:37Zen
dc.date.available2025-06-14T08:00:37Zen
dc.date.issued2025-06-13en
dc.description.abstractgeneralAs our digital world becomes more connected, detecting unusual or harmful behavior on networks is more important than ever. Traditional systems that monitor for cyber threats often rely on fixed rules or need labeled examples of attacks, which makes them less effective in real-world, fast-changing environments. This thesis introduces Tenko, a smarter and more adaptable system that identifies suspicious activity on networks in real time—without needing prior knowledge of what an attack looks like. Built as an improvement to an earlier system called Kitsune, Tenko keeps track of how devices behave over time, rather than treating each activity as an isolated event. This means it can better recognize when a device gradually starts acting suspicious, while avoiding false alarms from short-lived or harmless changes. What sets Tenko apart is its ability to learn and adjust dynamically. It uses a lightweight memory system to remember past behaviors and prioritize more recent ones, helping it make more accurate decisions. It also includes a secure blockchain-based method to store and share trust information about devices, which allows the system to work across different parts of a network while staying secure and tamper-proof. To test its performance, Tenko was evaluated on a set of real-world network attacks and showed clear improvements over existing methods—detecting more threats while creating fewer false alarms and missing fewer attacks. This research offers a practical and scalable way to improve cybersecurity, especially in systems where threats evolve constantly and fast, such as smart homes, IoT networks, and critical infrastructure.en
dc.description.degreeMaster of Scienceen
dc.format.mediumETDen
dc.identifier.othervt_gsexam:44185en
dc.identifier.urihttps://hdl.handle.net/10919/135515en
dc.language.isoenen
dc.publisherVirginia Techen
dc.rightsIn Copyrighten
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/en
dc.subjectIntrusion Detection Systemen
dc.subjectZero Trust Architectureen
dc.titleTenko: A Zero Trust Inspired Framework for Real-Time Network Defense via Intelligent Thresholding and Node-Level Anomaly Scoringen
dc.typeThesisen
thesis.degree.disciplineComputer Science & Applicationsen
thesis.degree.grantorVirginia Polytechnic Institute and State Universityen
thesis.degree.levelmastersen
thesis.degree.nameMaster of Scienceen

Files

Original bundle
Now showing 1 - 1 of 1
Name:
Bhola_S_T_2025.pdf
Size:
4.5 MB
Format:
Adobe Portable Document Format

Collections