End-To-End Anomaly Detection for Identifying Malicious Cyber Behavior through NLP-Based Log Embeddings

08/27/2021
by   Andrew Golczynski, et al.
0

Rule-based IDS (intrusion detection systems) are being replaced by more robust neural IDS, which demonstrate great potential in the field of Cybersecurity. However, these ML approaches continue to rely on ad-hoc feature engineering techniques, which lack the capacity to vectorize inputs in ways that are fully relevant to the discovery of anomalous cyber activity. We propose a deep end-to-end framework with NLP-inspired components for identifying potentially malicious behaviors on enterprise computer networks. We also demonstrate the efficacy of this technique on the recently released DARPA OpTC data set.

READ FULL TEXT
research
04/21/2021

Robustness of ML-Enhanced IDS to Stealthy Adversaries

Intrusion Detection Systems (IDS) enhanced with Machine Learning (ML) ha...
research
03/07/2020

Machine Learning based Anomaly Detection for 5G Networks

Protecting the networks of tomorrow is set to be a challenging domain du...
research
09/18/2020

Experimental Review of Neural-based approaches for Network Intrusion Management

The use of Machine Learning (ML) techniques in Intrusion Detection Syste...
research
03/19/2019

Spline Based Intrusion Detection in Vehicular Ad Hoc Networks (VANET)

Intrusion detection systems (IDSs) play a crucial role in the identifica...
research
09/10/2018

Open Problems in Robotic Anomaly Detection

Failures in robotics can have disastrous consequences that worsen rapidl...
research
12/02/2017

Recurrent Neural Network Language Models for Open Vocabulary Event-Level Cyber Anomaly Detection

Automated analysis methods are crucial aids for monitoring and defending...
research
04/06/2023

From Explanation to Action: An End-to-End Human-in-the-loop Framework for Anomaly Reasoning and Management

Anomalies are often indicators of malfunction or inefficiency in various...

Please sign up or login with your details

Forgot password? Click here to reset