An Advanced Approach for Detecting Behavior-Based Intranet Attacks by Machine Learning

被引:0
|
作者
Jang, Myongwon [1 ]
Lee, Kyungho [1 ]
机构
[1] Korea Univ, Sch Cybersecur, Seoul 02841, South Korea
关键词
Cybersecurity; intranet attack; Zeek IDS; feature engineering (FE); machine learning (ML);
D O I
10.1109/ACCESS.2024.3387016
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
To address continuously increasing cyber threats, security professionals within organizations are fortifying internal security by implementing security policies such as network segregation and emerging concepts such as Zero Trust. However, despite these changes in the cybersecurity landscape, the ultimate goal of cyber attackers, which is to exfiltrate critical information stored within an organization's intranet, remains unchanged. Consequently, attackers with motives such as hacktivists persistently and repeatedly target key systems within an organization's intranet to achieve their ultimate objectives. Considering the tendencies of intranet attackers, this study proposes the inclusion of the number of connection attempts for attack detection as an additional attribute alongside commonly used attributes such as source IP, destination IP, protocol, and attack signatures in intrusion detection rules. This proposal is supported by establishing an experimental environment for conducting intranet attacks and collecting raw data. Using feature engineering techniques, the raw data were transformed into analyzable datasets, and the performance was measured using six supervised machine learning algorithms. Through this research, we aim to contribute to the field of cybersecurity by going beyond the conventional focus on Internet-based attacks and providing a methodology for analyzing various intranet-based attacks in a post-stage environment. In addition, we share the method of feature engineering Zeek IDS raw data and release the resulting dataset to further advance the field. We hope that these contributions will foster future developments in this domain.
引用
收藏
页码:52480 / 52495
页数:16
相关论文
共 50 条
  • [21] A lightweight machine learning based security framework for detecting phishing attacks
    Kumar, Yogendra
    Subba, Basant
    2021 INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2021, : 184 - 188
  • [22] A Holistic Approach for Detecting DDoS Attacks by Using Ensemble Unsupervised Machine Learning
    Das, Saikat
    Venugopal, Deepak
    Shiva, Sajjan
    ADVANCES IN INFORMATION AND COMMUNICATION, VOL 2, 2020, 1130 : 721 - 738
  • [23] An Ensemble Machine Learning Approach for Detecting and Classifying Malware Attacks on Mobile Devices
    Alsharif, Eiman
    Alharby, Maher
    ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2025,
  • [24] Detecting APT Attacks Based on Network Traffic Using Machine Learning
    Xuan, Cho Do
    JOURNAL OF WEB ENGINEERING, 2021, 20 (01): : 171 - 190
  • [25] Detecting Emergent Behavior in Complex Systems: A Machine Learning Approach
    Dahia, Simranjeet Singh
    Szabo, Claudia
    PROCEEDINGS OF THE 38TH ACM SIGSIM INTERNATIONAL CONFERENCE ON PRINCIPLES OF ADVANCED DISCRETE SIMULATION, ACM SIGSIM-PADS 2024, 2024, : 81 - 87
  • [26] Detecting Low-Quality Workers in QoE Crowdtesting: A Worker Behavior-Based Approach
    Mok, Ricky K. P.
    Chang, Rocky K. C.
    Li, Weichao
    IEEE TRANSACTIONS ON MULTIMEDIA, 2017, 19 (03) : 530 - 543
  • [27] An architecture for behavior-based reinforcement learning
    Konidaris, GD
    Hayes, GM
    ADAPTIVE BEHAVIOR, 2005, 13 (01) : 5 - 32
  • [28] Machine-Learning Techniques for Detecting Attacks in SDN
    Elsayed, Mahmoud Said
    Nhien-An Le-Khac
    Dev, Soumyabrata
    Jurcut, Anca Delia
    PROCEEDINGS OF 2019 IEEE 7TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2019), 2019, : 277 - 281
  • [29] Detecting Spear Phishing Attacks Using Machine Learning
    Regulagadda, Ramakrishna
    Krishna, M. Sai
    Prasanth, G.
    Sumalatha, V
    Ramesh, Y. Sai
    INTERNATIONAL JOURNAL OF EARLY CHILDHOOD SPECIAL EDUCATION, 2022, 14 (05) : 1457 - 1459
  • [30] Evaluating Machine Learning Algorithms for Detecting DDoS Attacks
    Suresh, Manjula
    Anitha, R.
    ADVANCES IN NETWORK SECURITY AND APPLICATIONS, 2011, 196 : 441 - 452