Machine Learning Methods of Intelligent System Event Analysis for Multistep Cyberattack Detection

被引:0
|
作者
Kotenko, I. V. [1 ]
Levshun, D. A. [1 ]
机构
[1] Russian Acad Sci, St Petersburg Fed Res Ctr, St Petersburg 199178, Russia
基金
俄罗斯科学基金会;
关键词
intelligent systems; knowledge bases; cybersecurity; multistep attack; security events; incident management; ATTACKS;
D O I
10.3103/S0147688224700254
中图分类号
G25 [图书馆学、图书馆事业]; G35 [情报学、情报工作];
学科分类号
1205 ; 120501 ;
摘要
This study presents a classification and comparative analysis of intelligent system event methods for detecting multistep cyberattacks. Such attacks are a sequence of interrelated steps taken by the attacker pursuing a specific goal of intrusion. The paper analyzes approaches to multistep cyberattack detection using machine learning on system event data, including supervised learning, unsupervised learning, and semi-supervised learning. The approaches considered are analyzed according to the following criteria: the method of extracting knowledge about scenarios of system events and attacks, the scenario knowledge representation method, the security events analysis method, the security problem to be solved, and the data set used. The paper exposes the main advantages and disadvantages of machine learning approaches to detecting multistep cyberattacks as well as possible research directions in this domain.
引用
收藏
页码:372 / 381
页数:10
相关论文
共 50 条
  • [41] Analysis of Machine Learning Techniques Applied to Sensory Detection of Vehicles in Intelligent Crosswalks
    Lozano Dominguez, Jose Manuel
    Al-Tam, Faroq
    Mateo Sanguino, Tomas de J.
    Correia, Noelia
    SENSORS, 2020, 20 (21) : 1 - 19
  • [42] Comparison of machine learning methods for intelligent tutoring systems
    Hamalainen, Wilhelmiina
    Vinni, Mikko
    INTELLIGENT TUTORING SYSTEMS, PROCEEDINGS, 2006, 4053 : 525 - 534
  • [43] INTELLIGENT WEB CACHING USING MACHINE LEARNING METHODS
    Sulaiman, Sarina
    Shamsuddin, Siti Mariyam
    Abraham, Ajith
    Sulaiman, Shahida
    NEURAL NETWORK WORLD, 2011, 21 (05) : 429 - 452
  • [44] Machine Learning Methods for Intelligent Abnormal Brain Identification
    Liu, Fangyuan
    Lu, Siyuan
    Snetkov, Leonid
    PROCEEDINGS OF THE 2017 INTERNATIONAL CONFERENCE ON APPLIED MATHEMATICS, MODELLING AND STATISTICS APPLICATION (AMMSA 2017), 2017, 141 : 420 - 422
  • [45] LADS: A Live Anomaly Detection System based on Machine Learning Methods
    Gonzalez-Granadillo, Gustavo
    Diaz, Rodrigo
    Medeiros, Iberia
    Gonzalez-Zarzosa, Susana
    Machnicki, Dawid
    PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS, VOL 2: SECRYPT, 2019, : 464 - 469
  • [46] IoT Multi-Vector Cyberattack Detection Based on Machine Learning Algorithms: Traffic Features Analysis, Experiments, and Efficiency
    Lysenko, Sergii
    Bobrovnikova, Kira
    Kharchenko, Vyacheslav
    Savenko, Oleg
    ALGORITHMS, 2022, 15 (07)
  • [47] Detection of Intrusions with Machine Learning Methods
    Bostanci, Beyzanur
    Albayrak, Ahmet
    2ND INTERNATIONAL INFORMATICS AND SOFTWARE ENGINEERING CONFERENCE (IISEC), 2021,
  • [48] Classical and machine learning methods for event reconstruction in NeuLAND
    Mayer, Jan
    Boretzky, Konstanze
    Douma, Christiaan
    Hoemann, Elena
    Zilges, Andreas
    NUCLEAR INSTRUMENTS & METHODS IN PHYSICS RESEARCH SECTION A-ACCELERATORS SPECTROMETERS DETECTORS AND ASSOCIATED EQUIPMENT, 2021, 1013
  • [49] Research on Interpretable Methods of Machine Learning Applied in Intelligent Analysis of Power System (Part I): Basic Concept and Framework
    Pu T.
    Qiao J.
    Zhao Z.
    Zhao P.
    Zhongguo Dianji Gongcheng Xuebao/Proceedings of the Chinese Society of Electrical Engineering, 2023, 43 (18): : 7010 - 7029
  • [50] Intelligent intrusion detection system in smart grid using computational intelligence and machine learning
    Khan, Suleman
    Kifayat, Kashif
    Kashif Bashir, Ali
    Gurtov, Andrei
    Hassan, Mehdi
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2021, 32 (06)