Cyberattack event logs classification using deep learning with semantic feature analysis

被引:0
|
作者
Alzu'bi, Ahmad [1 ]
Darwish, Omar [2 ]
Albashayreh, Amjad [1 ]
Tashtoush, Yahya [1 ]
机构
[1] Jordan Univ Sci & Technol, Dept Comp Sci, Irbid, Jordan
[2] Eastern Michigan Univ, Informat Secur & Appl Comp, Ypsilanti, MI USA
关键词
Cyberattack; Event logs; Intrusion detection; Deep learning; BERT;
D O I
10.1016/j.cose.2024.104222
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Event logs playa crucial role in cybersecurity by detecting potentially malicious network activities and preventing data loss or theft. Previous work did not place a high value on log messages and their impact on security breach prediction and intrusion detection. This research paper introduces a novel approach for log message analysis applied to a dataset of event logs collected from various web sources. Event log messages were analyzed and categorized based on event and attack types with an explainable AI emphasizing the value of its key data. The study aims to enhance intrusion detection and minimize performance degradation by identifying suspicious events. In this regard, anew semantic vectorization framework is proposed, leveraging deep learning architectures to develop semantic discriminating log features, offering a cogent explanation and classification of event log messages. The use of BERT deep embeddings as a baseline for the prediction model allows for visualizing and interpreting the formulation of log message semantic features. Several empirical scenarios are set and conducted extensively to evaluate the performance of the event log classifier, considering the attack type, event type, and zero-shot logs. The experimental results demonstrate that the proposed event log classifier outperforms state-of-the-art machine learning models, achieving a recall of 99.27% and a precision of 99.29%. This highlights the model's ability to accurately identify events of a particular type by detecting as many suspicious events as feasible while minimizing the misclassification rate.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Unsupervised feature learning and automatic modulation classification using deep learning model
    Ali, Afan
    Fan Yangyu
    PHYSICAL COMMUNICATION, 2017, 25 : 75 - 84
  • [22] Fusion of deep learning based cyberattack detection and classification model for intelligent systems
    Omar A. Alzubi
    Issa Qiqieh
    Jafar A. Alzubi
    Cluster Computing, 2023, 26 : 1363 - 1374
  • [23] DEEP LEARNING BASED CLASSIFICATION USING SEMANTIC INFORMATION FOR POLSAR IMAGE
    Zhang, Lu
    Xie, Wen
    Zhao, Feng
    Liu, Hanqiang
    Duan, Yiping
    IGARSS 2020 - 2020 IEEE INTERNATIONAL GEOSCIENCE AND REMOTE SENSING SYMPOSIUM, 2020, : 196 - 199
  • [24] A Deep Learning Method for Android Application Classification Using Semantic Features
    Wang, Zhiqiang
    Li, Gefei
    Zhuo, Zihan
    Ren, Xiaorui
    Lin, Yuheng
    Gu, Jieming
    SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [25] A Semantic Framework Supporting Business Process Variability Using Event Logs
    Yongsiriwit, Karn
    Sellami, Mohamed
    Gaaloul, Walid
    PROCEEDINGS 2016 IEEE INTERNATIONAL CONFERENCE ON SERVICES COMPUTING (SCC 2016), 2016, : 163 - 170
  • [26] NetFlow Monitoring and Cyberattack Detection Using Deep Learning With Ceph
    Yang, Chao-Tung
    Liu, Jung-Chun
    Kristiani, Endah
    Liu, Ming-Lun
    You, Ilsun
    Pau, Giovanni
    IEEE ACCESS, 2020, 8 : 7842 - 7850
  • [27] Anomaly Detection in Logs Using Deep Learning
    Aziz, Ayesha
    Munir, Kashif
    IEEE ACCESS, 2024, 12 : 176124 - 176135
  • [28] Deep semantic learning for acoustic scene classification
    Shao, Yun-Fei
    Ma, Xin-Xin
    Ma, Yong
    Zhang, Wei-Qiang
    EURASIP JOURNAL ON AUDIO SPEECH AND MUSIC PROCESSING, 2024, 2024 (01)
  • [29] Semantic enhanced deep learning for image classification
    Li, Siguang
    Li, Maozhen
    Jiang, Changjun
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2018, 30 (23):
  • [30] Deep semantic learning for acoustic scene classification
    Yun-Fei Shao
    Xin-Xin Ma
    Yong Ma
    Wei-Qiang Zhang
    EURASIP Journal on Audio, Speech, and Music Processing, 2024