Cyberattack Detection Framework Using Machine Learning and User Behavior Analytics  被引量:1

在线阅读下载全文

作  者:Abdullah Alshehri Nayeem Khan Ali Alowayr Mohammed Yahya Alghamdi 

机构地区:[1]Information Technology Department,Faculty of Computer Science and Information Technology,Al Baha University,Al Baha,65799,Saudi Arabia [2]Computer Science Department,Faculty of Science and Arts at Buljurashi,Al Baha University,Al Baha,65799,Saudi Arabia

出  处:《Computer Systems Science & Engineering》2023年第2期1679-1689,共11页计算机系统科学与工程(英文)

基  金:supported by the fund received from Al Baha University,8/1440.

摘  要:This paper proposes a novel framework to detect cyber-attacks using Machine Learning coupled with User Behavior Analytics.The framework models the user behavior as sequences of events representing the user activities at such a network.The represented sequences are thenfitted into a recurrent neural network model to extract features that draw distinctive behavior for individual users.Thus,the model can recognize frequencies of regular behavior to profile the user manner in the network.The subsequent procedure is that the recurrent neural network would detect abnormal behavior by classifying unknown behavior to either regu-lar or irregular behavior.The importance of the proposed framework is due to the increase of cyber-attacks especially when the attack is triggered from such sources inside the network.Typically detecting inside attacks are much more challenging in that the security protocols can barely recognize attacks from trustful resources at the network,including users.Therefore,the user behavior can be extracted and ultimately learned to recognize insightful patterns in which the regular patterns reflect a normal network workflow.In contrast,the irregular patterns can trigger an alert for a potential cyber-attack.The framework has been fully described where the evaluation metrics have also been introduced.The experimental results show that the approach performed better compared to other approaches and AUC 0.97 was achieved using RNN-LSTM 1.The paper has been concluded with pro-viding the potential directions for future improvements.

关 键 词:CYBERSECURITY deep learning machine learning user behavior analytics 

分 类 号:TP393.08[自动化与计算机技术—计算机应用技术] TP181[自动化与计算机技术—计算机科学与技术]

 

参考文献:

正在载入数据...

 

二级参考文献:

正在载入数据...

 

耦合文献:

正在载入数据...

 

引证文献:

正在载入数据...

 

二级引证文献:

正在载入数据...

 

同被引文献:

正在载入数据...

 

相关期刊文献:

正在载入数据...

相关的主题
相关的作者对象
相关的机构对象