arrow
返回

Modeling and analyzing attacker behavior in IoT botnet using temporal convolution network (TCN)

delete2022-06-01
delete9
delete
OA
AI
F
Farhan Sadique *
S
Shamik Sengupta
DOI:10.1016/j.cose.2022.102714delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Traditional reactive approach of blacklisting botnets fails to adapt to the rapidly evolving landscape of cyberattacks. An automated and proactive approach to detect and block botnet hosts will immensely benefit the industry. Behavioral analysis of attackers is shown to be effective against a wide variety of attack types. Previous works, however, focus solely on anomalies in network traffic to detect bots and botnet. In this work we take a more robust approach of analyzing the heterogeneous events including network traffic, file download events, SSH logins and chain of commands input by attackers in a compromised host. We have deployed several honeypots to simulate Linux shells and allowed attackers access to the shells. We have collected a large dataset of heterogeneous threat events from the honeypots. We have then combined and modeled the heterogeneous threat data to analyze attacker behavior. Then we have used a deep learning architecture called a Temporal Convolutional Network (TCN) to do sequential and predictive analysis on the data. A prediction accuracy of 85 - 97% validates our data model as well as our analysis methodology. In this work, we have also developed an automated mechanism to collect and analyze these data. For the automation we have used CYbersecurity information Exchange (CYBEX). Finally, we have compared TCN with Long Short-Term Memory (LSTM) and Gated Recurrent Unit (GRU) and have showed that TCN outperforms LSTM and GRU for the task at hand.(c) 2022 Published by Elsevier Ltd.
Keyword:
Temporal convolutional network
TCN
LSTM
Cowrie honeypot
Command
CYBEX
Attacker behavior modeling
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

N
nevada system of higher education (nshe)
学者数:
1.4W
论文数: 1.3W
被引数: 30
引用论文

引用论文

BotDet: A System for Real Time Botnet Command and Control Traffic Detection
err2018-01-01
err37
errOAAI
errGhafir, Ibrahim; Prenosil, Vaclav; Hammoudeh, Mohammad; Baker, Thar; Jabbar, Sohail; Khalid, Shehzad; Jaf, Sardar
err分享
err收藏
err分享
err收藏
A high temperature variety of BiOF一种高温品种的BiOF
err1983-09-01
err0
PREAI
errSamir Matar; Jean-Maurice Reau; Louis Rabardel; Gérard Demazeau; Paul Hagenmuller
err分享
err收藏
Mixed-Model Regression Analysis and Dealing with Interindividual Differences
err2004-01-01
err0
PREAI
errHans P.A Van Dongen; Erik Olofsen; David F Dinges; Greg Maislin
err分享
err收藏
Intrusion detection system: A comprehensive review
err2013-01-01
err897
PREAI
errLiao, Hung-Jen; Lin, Chun-Hung Richard; Lin, Ying-Chih; Tung, Kuang-Yuan
err分享
err收藏
没有更多内容