Two-stage multi-datasource machine learning for attack technique and lifecycle detection

被引:0
|
作者
Lin, Ying-Dar [1 ]
Yang, Shin-Yi [1 ]
Sudyana, Didik [1 ]
Yudha, Fietyata [1 ]
Lai, Yuan-Cheng [2 ]
Hwang, Ren-Hung [3 ]
机构
[1] Natl Yang Ming Chiao Tung Univ, Dept Comp Sci, Hsinchu 300, Taiwan
[2] Natl Taiwan Univ Sci & Technol, Dept Informat Management, Taipei 10607, Taiwan
[3] Natl Yang Ming Chiao Tung Univ, Coll Artificial Intelligence, Tainan 711, Taiwan
关键词
Ml-based IDS; Attack lifecycle detection; Multi-datasource IDS; Two-stage lifecycle detection; CHALLENGES;
D O I
10.1016/j.cose.2024.103859
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion detection systems (IDS) have increasingly adopted machine learning (ML) techniques to enhance their ability to detect a wide range of attack variants. However, the traditional focus in current research primarily revolves around identifying specific attack types or techniques using a single data source. However, this approach lacks a holistic perspective on attacks, which can result in missed detections. To improve the effectiveness of responding to detected attacks, it is essential to identify them based on their lifecycles and incorporate information from multiple data sources. In this study, we present three distinct approaches for detecting attack lifecycles, each leveraging different ML methodologies: a single -stage ML model, a two -stage ML+ML approach, and ML with sequence matching (ML+SM). Simultaneously, we explore the benefits of utilizing multiple data sources, including network traffic, system logs, and host statistics, to enhance technique detection capabilities. Our evaluation of these methods reveals that on lifecycle detection, the two -stage ML+ML approach outperforms the others, achieving an impressive F1 score of 0.994. In contrast, the singlestage and ML+SM methods yield F1 scores of 0.887 and 0.189, respectively. Furthermore, the integration of multiple data sources proves highly advantageous, with the combination of all three sources yielding the highest F1 score of 0.922 on technique detection.
引用
收藏
页数:14
相关论文
共 50 条
  • [31] A Two-stage Learning Approach for Traffic Sign Detection and Recognition
    Chiu, Ying-Chi
    Lin, Huei-Yung
    Tai, Wen-Lung
    PROCEEDINGS OF THE 7TH INTERNATIONAL CONFERENCE ON VEHICLE TECHNOLOGY AND INTELLIGENT TRANSPORT SYSTEMS (VEHITS), 2021, : 276 - 283
  • [32] Two-Stage Hybrid Extreme Learning Machine for Sequential Imbalanced Data
    Mao, Wentao
    Wang, Jinwan
    He, Ling
    Tian, Yangyang
    PROCEEDINGS OF ELM-2015, VOL 1: THEORY, ALGORITHMS AND APPLICATIONS (I), 2016, 6 : 423 - 433
  • [33] ToCoAD: Two-Stage Contrastive Learning for Industrial Anomaly Detection
    Liang, Yun
    Hu, Zhiguang
    Huang, Junjie
    Di, Donglin
    Su, Anyang
    Fan, Lei
    IEEE TRANSACTIONS ON INSTRUMENTATION AND MEASUREMENT, 2025, 74
  • [34] Two-stage extreme learning machine for high-dimensional data
    Peng Liu
    Yihua Huang
    Lei Meng
    Siyuan Gong
    Guopeng Zhang
    International Journal of Machine Learning and Cybernetics, 2016, 7 : 765 - 772
  • [35] Two-Stage Hybrid Malware Detection Using Deep Learning
    Baek, Seungyeon
    Jeon, Jueun
    Jeong, Byeonghui
    Jeong, Young-Sik
    HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2021, 11
  • [36] Prediction of lattice thermal conductivity with two-stage interpretable machine learning
    Hu, Jinlong
    Zuo, Yuting
    Hao, Yuzhou
    Shu, Guoyu
    Wang, Yang
    Feng, Minxuan
    Li, Xuejie
    Wang, Xiaoying
    Sun, Jun
    Ding, Xiangdong
    Gao, Zhibin
    Zhu, Guimei
    Li, Baowen
    CHINESE PHYSICS B, 2023, 32 (04)
  • [37] Two-Stage Electricity Demand Modeling Using Machine Learning Algorithms
    Gajowniczek, Krzysztof
    Zabkowski, Tomasz
    ENERGIES, 2017, 10 (10)
  • [38] Predicting Stock Price Using Two-Stage Machine Learning Techniques
    Jun Zhang
    Lan Li
    Wei Chen
    Computational Economics, 2021, 57 : 1237 - 1261
  • [39] Machine Learning for K-Adaptability in Two-Stage Robust Optimization
    Julien, Esther
    Postek, Krzysztof
    Birbil, S. llker
    INFORMS JOURNAL ON COMPUTING, 2024,
  • [40] Two-stage extreme learning machine for high-dimensional data
    Liu, Peng
    Huang, Yihua
    Meng, Lei
    Gong, Siyuan
    Zhang, Guopeng
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2016, 7 (05) : 765 - 772