Cyber Situation Awareness with Active Learning for Intrusion Detection

12/29/2019
by   Steven McElwee, et al.
0

Intrusion detection has focused primarily on detecting cyberattacks at the event-level. Since there is such a large volume of network data and attacks are minimal, machine learning approaches have focused on improving accuracy and reducing false positives, but this has frequently resulted in overfitting. In addition, the volume of intrusion detection alerts is large and creates fatigue in the human analyst who must review them. This research addresses the problems associated with event-level intrusion detection and the large volumes of intrusion alerts by applying active learning and cyber situation awareness. This paper includes the results of two experiments using the UNSW-NB15 dataset. The first experiment evaluated sampling approaches for querying the oracle, as part of active learning. It then trained a Random Forest classifier using the samples and evaluated its results. The second experiment applied cyber situation awareness by aggregating the detection results of the first experiment and calculating the probability that a computer system was part of a cyberattack. This research showed that moving the perspective of event-level alerts to the probability that a computer system was part of an attack improved the accuracy of detection and reduced the volume of alerts that a human analyst would need to review.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/04/2018

Active Learning for Wireless IoT Intrusion Detection

Internet of Things (IoT) is becoming truly ubiquitous in our everyday li...
research
05/10/2021

ADASYN-Random Forest Based Intrusion Detection Model

Intrusion detection has been a key topic in the field of cyber security,...
research
08/28/2022

Research on Network Security Situational Awareness Based on Crawler Algorithm

Network security situation awareness is a critical basis for security so...
research
04/02/2019

Active Learning for Network Intrusion Detection

Network operators are generally aware of common attack vectors that they...
research
07/13/2023

A Controlled Experiment on the Impact of Intrusion Detection False Alarm Rate on Analyst Performance

Organizations use intrusion detection systems (IDSes) to identify harmfu...
research
02/24/2020

Cry Wolf: Toward an Experimentation Platform and Dataset for Human Factors in Cyber Security Analysis

Computer network defense is a partnership between automated systems and ...
research
01/29/2020

Intrusion Detection Systems: A Cross-Domain Overview

The cybersecurity ecosystem continuously changes with the growth of cybe...

Please sign up or login with your details

Forgot password? Click here to reset