Honeyboost: Boosting honeypot performance with data fusion and anomaly detection

05/06/2021
by   Sevvandi Kandanaarachchi, et al.
0

With cyber incidents and data breaches becoming increasingly common, being able to predict a cyberattack has never been more crucial. Network Anomaly Detection Systems (NADS) ability to identify unusual behavior makes them useful in predicting such attacks. In this paper, we introduce a novel framework to enhance the performance of honeypot aided NADS. We use a hybrid of two approaches: horizontal and vertical. The horizontal approach constructs a time series from the communications of each node, with node-level features encapsulating their behavior over time. The vertical approach finds anomalies in each protocol space. To the best of our knowledge, this is the first time node-level features have been used in honeypot aided NADS. Furthermore, using extreme value theory, anomaly detection with low false positive rates is possible. Experimental results indicate the efficacy of our framework in identifying suspicious activities of nodes from node-level features, often before the honeypot does.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/27/2022

FadMan: Federated Anomaly Detection across Multiple Attributed Networks

Anomaly subgraph detection has been widely used in various applications,...
research
06/27/2023

Precursor-of-Anomaly Detection for Irregular Time Series

Anomaly detection is an important field that aims to identify unexpected...
research
12/06/2018

Cyber Anomaly Detection Using Graph-node Role-dynamics

Intrusion detection systems (IDSs) generate valuable knowledge about net...
research
11/27/2019

High- and Low-level image component decomposition using VAEs for improved reconstruction and anomaly detection

Variational Auto-Encoders have often been used for unsupervised pretrain...
research
10/31/2018

A framework for automated anomaly detection in high frequency water-quality data from in situ sensors

River water-quality monitoring is increasingly conducted using automated...
research
11/10/2020

Building an Automated and Self-Aware Anomaly Detection System

Organizations rely heavily on time series metrics to measure and model k...
research
06/02/2023

A Hybrid Approach for Smart Alert Generation

Anomaly detection is an important task in network management. However, d...

Please sign up or login with your details

Forgot password? Click here to reset