arrow
返回

Two-stage multi-datasource machine learning for attack technique and lifecycle detection

delete2024-07-01
delete0
PRE
AI
Y
Ying‐Dar Lin
S
Shin‐Yi Yang
D
Didik Sudyana *
F
Fietyata Yudha
Y
Yuan‐Cheng Lai
R
Ren‐Hung Hwang
DOI:10.1016/j.cose.2024.103859delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Intrusion detection systems (IDS) have increasingly adopted machine learning (ML) techniques to enhance their ability to detect a wide range of attack variants. However, the traditional focus in current research primarily revolves around identifying specific attack types or techniques using a single data source. However, this approach lacks a holistic perspective on attacks, which can result in missed detections. To improve the effectiveness of responding to detected attacks, it is essential to identify them based on their lifecycles and incorporate information from multiple data sources. In this study, we present three distinct approaches for detecting attack lifecycles, each leveraging different ML methodologies: a single -stage ML model, a two -stage ML+ML approach, and ML with sequence matching (ML+SM). Simultaneously, we explore the benefits of utilizing multiple data sources, including network traffic, system logs, and host statistics, to enhance technique detection capabilities. Our evaluation of these methods reveals that on lifecycle detection, the two -stage ML+ML approach outperforms the others, achieving an impressive F1 score of 0.994. In contrast, the singlestage and ML+SM methods yield F1 scores of 0.887 and 0.189, respectively. Furthermore, the integration of multiple data sources proves highly advantageous, with the combination of all three sources yielding the highest F1 score of 0.922 on technique detection.
Keyword:
Ml-based IDS
Attack lifecycle detection
Multi-datasource IDS
Two-stage lifecycle detection

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

N
National Yang Ming Chiao Tung University
学者数:
2.5W
论文数: 2.3W
被引数: 2.2W
N
national taiwan university of science & technology
学者数:
8.8K
论文数: 8.7K
被引数: 9
引用论文

引用论文

Transformer-based framework for alert aggregation and attack prediction in a multi-stage attack
err2024-01-01
err6
PREAI
errWang, Wenbo; Yi, Peng; Jiang, Junfang; Zhang, Peng; Chen, Xiang
err分享
err收藏
Arsenic removal from aqueous solutions by adsorption using novel MIL-53(Fe) as a highly efficient adsorbent使用新型MIL-53(Fe) 作为高效吸附剂通过吸附从水溶液中去除砷
err2015-01-01
err0
PREAI
errTuan. A. Vu; Giang. H. Le; Canh. D. Dao; Lan. Q. Dang; Kien. T. Nguyen; Quang. K. Nguyen; Phuong. T. Dang; Hoa. T. K. Tran; Quang. T. Duong; Tuyen. V. Nguyen; Gun. D. Lee
err分享
err收藏
err分享
err收藏
Comparative research on network intrusion detection methods based on machine learning
err2022-10-01
err38
PREAI
errZhang, Chunying; Jia, Donghao; Wang, Liya; Wang, Wenjie; Liu, Fengchun; Yang, Aimin
err分享
err收藏
Detecting APT attacks using an attack intent-driven and sequence-based learning approach
err2024-05-01
err2
PREAI
errYue, Hao; Li, Tong; Wu, Di; Zhang, Runzi; Yang, Zhen
err分享
err收藏
Ransomware: Recent advances, analysis, challenges and future research directions
err2021-12-01
err76
errOAAI
errBeaman, Craig; Barkworth, Ashley; Akande, Toluwalope David; Hakak, Saqib; Khan, Muhammad Khurram
err分享
err收藏
学者 查看更多内容