Cyberattack event logs classification using deep learning with semantic feature analysis

被引:0
|
作者
Alzu'bi, Ahmad [1 ]
Darwish, Omar [2 ]
Albashayreh, Amjad [1 ]
Tashtoush, Yahya [1 ]
机构
[1] Jordan Univ Sci & Technol, Dept Comp Sci, Irbid, Jordan
[2] Eastern Michigan Univ, Informat Secur & Appl Comp, Ypsilanti, MI USA
关键词
Cyberattack; Event logs; Intrusion detection; Deep learning; BERT;
D O I
10.1016/j.cose.2024.104222
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Event logs playa crucial role in cybersecurity by detecting potentially malicious network activities and preventing data loss or theft. Previous work did not place a high value on log messages and their impact on security breach prediction and intrusion detection. This research paper introduces a novel approach for log message analysis applied to a dataset of event logs collected from various web sources. Event log messages were analyzed and categorized based on event and attack types with an explainable AI emphasizing the value of its key data. The study aims to enhance intrusion detection and minimize performance degradation by identifying suspicious events. In this regard, anew semantic vectorization framework is proposed, leveraging deep learning architectures to develop semantic discriminating log features, offering a cogent explanation and classification of event log messages. The use of BERT deep embeddings as a baseline for the prediction model allows for visualizing and interpreting the formulation of log message semantic features. Several empirical scenarios are set and conducted extensively to evaluate the performance of the event log classifier, considering the attack type, event type, and zero-shot logs. The experimental results demonstrate that the proposed event log classifier outperforms state-of-the-art machine learning models, achieving a recall of 99.27% and a precision of 99.29%. This highlights the model's ability to accurately identify events of a particular type by detecting as many suspicious events as feasible while minimizing the misclassification rate.
引用
收藏
页数:15
相关论文
共 50 条
  • [31] Image Classification and Semantic Segmentation with Deep Learning
    Quazi, Saiman
    Musa, Sarhan M.
    6TH IEEE INTERNATIONAL CONFERENCE ON RECENT ADVANCES AND INNOVATIONS IN ENGINEERING (ICRAIE), 2021,
  • [32] Using deep learning for acoustic event classification: The case of natural disasters
    Ekpezu, Akon O.
    Wiafe, Isaac
    Katsriku, Ferdinand
    Yaokumah, Winfred
    JOURNAL OF THE ACOUSTICAL SOCIETY OF AMERICA, 2021, 149 (04): : 2926 - 2935
  • [33] Classification of Power Quality Events Using Deep Learning on Event Images
    Balouji, Ebrahim
    Salor, Ozgul
    2017 3RD INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION AND IMAGE ANALYSIS (IPRIA), 2017, : 216 - 221
  • [34] Classification of Traffic Event Tweets in Portuguese Language Using Deep Learning
    Teixeira, Estevan Barbara
    de Souza Moura, Pedro Nuno
    Vieira Campos, Carlos Alberto
    2022 INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING, IWCMC, 2022, : 566 - 571
  • [35] A Comprehensive Survey on Event Analysis Using Deep Learning
    Varshney, Abhilasha
    Lamba, Sonia
    Garg, Puneet
    Proceedings - 2022 5th International Conference on Computational Intelligence and Communication Technologies, CCICT 2022, 2022, : 146 - 150
  • [36] Class imbalanced data handling with cyberattack classification using Hybrid Salp Swarm Algorithm with deep learning approach
    Alabduallah, Bayan
    Maray, Mohammed
    Alruwais, Nuha
    Alabdan, Rana
    Darem, Abdulbasit A.
    Alallah, Fouad Shoie
    Alsini, Raed
    Yafoz, Ayman
    ALEXANDRIA ENGINEERING JOURNAL, 2024, 106 : 654 - 663
  • [37] Email classification Using Semantic Feature Space
    Yi, Yun Fei
    Li, Cheng Hua
    Song, Wei
    ALPIT 2008: SEVENTH INTERNATIONAL CONFERENCE ON ADVANCED LANGUAGE PROCESSING AND WEB INFORMATION TECHNOLOGY, PROCEEDINGS, 2008, : 32 - +
  • [38] Deep Semantic Feature Learning for Software Defect Prediction
    Wang, Song
    Liu, Taiyue
    Nam, Jaechang
    Tan, Lin
    IEEE TRANSACTIONS ON SOFTWARE ENGINEERING, 2020, 46 (12) : 1267 - 1293
  • [39] Shallow and deep learning for event relatedness classification
    Haneczok, Jacek
    Piskorski, Jakub
    INFORMATION PROCESSING & MANAGEMENT, 2020, 57 (06)
  • [40] Optimal Deep Learning-based Cyberattack Detection and Classification Technique on Social Networks
    Albraikan, Amani Abdulrahman
    Hassine, Siwar Ben Haj
    Fati, Suliman Mohamed
    Al-Wesabi, Fahd N.
    Hilal, Anwer Mustafa
    Motwakel, Abdelwahed
    Hamza, Manar Ahmed
    Al Duhayyim, Mesfer
    CMC-COMPUTERS MATERIALS & CONTINUA, 2022, 72 (01): : 907 - 923