Towards Attribution in Network Attacks: A Deep Learning-Based Robust Framework for Intrusion Detection and Adversarial Toolchain Identification

Loading...
Thumbnail Image

Contributor

Advisor

Editor

Performer

Department

Instructor

Depositor

Speaker

Researcher

Consultant

Interviewer

Interviewee

Narrator

Transcriber

Annotator

Journal Title

Journal ISSN

Volume Title

Publisher

Journal Name

Volume

Number/Issue

Starting Page

378

Ending Page

Alternative Title

Abstract

Network intrusion detection systems (NIDS) are pivotal in cybersecurity operations centers (CSOCs) for detecting malicious activities. While signature-based NIDS rely on predefined rules, anomaly-based NIDS utilize machine learning (ML) and deep learning (DL) to detect anomalies. However, these models face challenges such as susceptibility to evasion attacks and high false positives and negatives. This study proposes a novel defense framework integrating supervised and unsupervised learning paradigms to enhance NIDS capabilities. The framework accurately identifies known attacks, detects adversarial attacks and their toolchains, and distinguishes novel attacks. Experimental evaluations on benchmark network intrusion data sets demonstrate high detection accuracies. Motivated by the need to attribute attacks and understand adversary motivations, the framework includes a toolchain detection component, crucial for developing comprehensive threat intelligence and improving incident response in CSOCs.

Description

Citation

Extent

10

Format

Type

Conference Paper

Geographic Location

Time Period

Related To

Proceedings of the 58th Hawaii International Conference on System Sciences

Related To (URI)

Table of Contents

Rights

Attribution-NonCommercial-NoDerivatives 4.0 International

Rights Holder

Catalog Record

Local Contexts

Email libraryada-l@lists.hawaii.edu if you need this content in ADA-compliant format.