Anomaly Detection in Cybersecurity: Unsupervised, Graph-Based and Supervised Learning Methods in Adversarial Environments

05/14/2021
by   David A. Bierbrauer, et al.
0

Machine learning for anomaly detection has become a widely researched field in cybersecurity. Inherent to today's operating environment is the practice of adversarial machine learning, which attempts to circumvent machine learning models. In this work, we examine the feasibility of unsupervised learning and graph-based methods for anomaly detection in the network intrusion detection system setting, as well as leverage an ensemble approach to supervised learning of the anomaly detection problem. We incorporate a realistic adversarial training mechanism when training our supervised models to enable strong classification performance in adversarial environments. Our results indicate that the unsupervised and graph-based methods were outperformed in detecting anomalies (malicious activity) by the supervised stacking ensemble method with two levels. This model consists of three different classifiers in the first level, followed by either a Naive Bayes or Decision Tree classifier for the second level. We see that our model maintains an F1-score above 0.97 for malicious samples across all tested level two classifiers. Notably, Naive Bayes is the fastest level two classifier averaging 1.12 seconds while Decision Tree maintains the highest AUC score of 0.98.

READ FULL TEXT
research
04/14/2021

A Vision-based System for Traffic Anomaly Detection using Deep Learning and Decision Trees

Any intelligent traffic monitoring system must be able to detect anomali...
research
09/26/2019

RADE: Resource-Efficient Supervised Anomaly Detection Using Decision Tree-Based Ensemble Methods

Decision-tree-based ensemble classification methods (DTEMs) are a preval...
research
11/13/2018

Benchmarking datasets for Anomaly-based Network Intrusion Detection: KDD CUP 99 alternatives

Machine Learning has been steadily gaining traction for its use in Anoma...
research
12/15/2022

DOC-NAD: A Hybrid Deep One-class Classifier for Network Anomaly Detection

Machine Learning (ML) approaches have been used to enhance the detection...
research
06/05/2023

Comparative Study on Semi-supervised Learning Applied for Anomaly Detection in Hydraulic Condition Monitoring System

Condition-based maintenance is becoming increasingly important in hydrau...
research
07/21/2022

Comparative Study on Supervised versus Semi-supervised Machine Learning for Anomaly Detection of In-vehicle CAN Network

As the central nerve of the intelligent vehicle control system, the in-v...
research
04/01/2022

Identifying Exoplanets with Machine Learning Methods: A Preliminary Study

The discovery of habitable exoplanets has long been a heated topic in as...

Please sign up or login with your details

Forgot password? Click here to reset