返回
Two-stage multi-datasource machine learning for attack technique and lifecycle detection
DOI:10.1016/j.cose.2024.103859.png)
摘要
En 中文
Intrusion detection systems (IDS) have increasingly adopted machine learning (ML) techniques to enhance their ability to detect a wide range of attack variants. However, the traditional focus in current research primarily revolves around identifying specific attack types or techniques using a single data source. However, this approach lacks a holistic perspective on attacks, which can result in missed detections. To improve the effectiveness of responding to detected attacks, it is essential to identify them based on their lifecycles and incorporate information from multiple data sources. In this study, we present three distinct approaches for detecting attack lifecycles, each leveraging different ML methodologies: a single -stage ML model, a two -stage ML+ML approach, and ML with sequence matching (ML+SM). Simultaneously, we explore the benefits of utilizing multiple data sources, including network traffic, system logs, and host statistics, to enhance technique detection capabilities. Our evaluation of these methods reveals that on lifecycle detection, the two -stage ML+ML approach outperforms the others, achieving an impressive F1 score of 0.994. In contrast, the singlestage and ML+SM methods yield F1 scores of 0.887 and 0.189, respectively. Furthermore, the integration of multiple data sources proves highly advantageous, with the combination of all three sources yielding the highest F1 score of 0.922 on technique detection.
Keyword:
Ml-based IDS
Attack lifecycle detection
Multi-datasource IDS
Two-stage lifecycle detection
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Transformer-based framework for alert aggregation and attack prediction in a multi-stage attack
COMPUTERS & SECURITY
IF5.4
Arsenic removal from aqueous solutions by adsorption using novel MIL-53(Fe) as a highly efficient adsorbent使用新型MIL-53(Fe) 作为高效吸附剂通过吸附从水溶液中去除砷
RSC Advances
IF0
Comparative research on network intrusion detection methods based on machine learning
COMPUTERS & SECURITY
IF5.4
Detecting APT attacks using an attack intent-driven and sequence-based learning approach
COMPUTERS & SECURITY
IF5.4
Detecting Reconnaissance and Discovery Tactics from the MITRE ATT&CK Framework in Zeek Conn Logs Using Spark's Machine Learning in the Big Data Framework在大数据框架中使用Spark的机器学习从Zeek Conn的MITRE ATT & CK框架中检测侦察和发现策略
SENSORS
IF3.5
Ransomware: Recent advances, analysis, challenges and future research directions
COMPUTERS & SECURITY
IF5.4

