<p>The increasing sophistication of cyber threats has led to the identification of some major shortcomings associated with honeypots, which include staticness, inflexibility, and vulnerability to fingerprinting. The proposed work aims at overcoming the aforementioned shortcomings by creating an Explainability-Driven Adaptive Cyber Deception Control System capable of engaging in intelligent, interactive interactions with cyber attackers. The key goal of the proposed solution is to improve threat intelligence gathering and deception efficiency by leveraging the benefits of adaptability and explainability. Machine learning, XAI, behavioral profiling, and environment mutation are the four key components that form the backbone of the proposed pipeline system. A Random Forest classifier is used for classification of normal and malicious sessions based on behavioral features at the level of commands. An explainability-driven metric known as the Feature Dominance Deception Index (FDDI) is developed to guide deception approaches, whereas Behavioral Convergence Score (BCS) is considered to assess behavioral convergence of attackers. Intent recognition using kill chain methodology allows generating responses in context-dependent fashion, while the mutation engine creates unique environments in each session to prevent fingerprinting attacks. Furthermore, Reinforcement Learning (RL) layer based on Q-learning is added to the framework to adaptively make decisions by learning the best possible deception tactics over multiple sessions. The Deception Quality Score (DQS) metric is used to measure the quality of deception within each session. Moreover, the UNSW-NB15 network intrusion data set is employed for validating the proposed model. Through benchmarking based on the generated behavioral dataset, the Random Forest-based behavioral profiler yielded a classification accuracy of 90.0%, recall of 85.7%, and an F1-score of 92.3%. Thereafter, the end-to-end deployment of the proposed framework through Cowrie honeypot sessions yielded better deception effectiveness, giving a framework-level attack classification accuracy of 90.0% and a 77.0% improvement in threat intelligence extraction per session than baseline Cowrie deployment. Kill chain stages were identified for the evaluated cases, deception goals were accomplished for all sessions under testing, fingerprinting efforts by the attacker were unsuccessful, and high-quality deception was maintained. The reward per session for the RL agent ranges from + 0 to + 14.0 for different session types, resulting in the formation of a converged Q-table containing values of 21 out of 90 possible states. Additionally, the technique ensures the resistance against honeypot fingerprinting, and demonstrates resistance against evaluated fingerprinting attempts. As far as it is currently known, few previous works can be found which have managed to include explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework. The presented framework manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception. The research makes advances in the current state-of-the-art research by enabling passive honeypots to become intelligent autonomous systems for detecting cyber threats.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Explainability-driven adaptive cyber deception control system for autonomous network defense

  • Shreyashi Deb Roy,
  • Ganesh Khekare,
  • Sejal Chhajed

摘要

The increasing sophistication of cyber threats has led to the identification of some major shortcomings associated with honeypots, which include staticness, inflexibility, and vulnerability to fingerprinting. The proposed work aims at overcoming the aforementioned shortcomings by creating an Explainability-Driven Adaptive Cyber Deception Control System capable of engaging in intelligent, interactive interactions with cyber attackers. The key goal of the proposed solution is to improve threat intelligence gathering and deception efficiency by leveraging the benefits of adaptability and explainability. Machine learning, XAI, behavioral profiling, and environment mutation are the four key components that form the backbone of the proposed pipeline system. A Random Forest classifier is used for classification of normal and malicious sessions based on behavioral features at the level of commands. An explainability-driven metric known as the Feature Dominance Deception Index (FDDI) is developed to guide deception approaches, whereas Behavioral Convergence Score (BCS) is considered to assess behavioral convergence of attackers. Intent recognition using kill chain methodology allows generating responses in context-dependent fashion, while the mutation engine creates unique environments in each session to prevent fingerprinting attacks. Furthermore, Reinforcement Learning (RL) layer based on Q-learning is added to the framework to adaptively make decisions by learning the best possible deception tactics over multiple sessions. The Deception Quality Score (DQS) metric is used to measure the quality of deception within each session. Moreover, the UNSW-NB15 network intrusion data set is employed for validating the proposed model. Through benchmarking based on the generated behavioral dataset, the Random Forest-based behavioral profiler yielded a classification accuracy of 90.0%, recall of 85.7%, and an F1-score of 92.3%. Thereafter, the end-to-end deployment of the proposed framework through Cowrie honeypot sessions yielded better deception effectiveness, giving a framework-level attack classification accuracy of 90.0% and a 77.0% improvement in threat intelligence extraction per session than baseline Cowrie deployment. Kill chain stages were identified for the evaluated cases, deception goals were accomplished for all sessions under testing, fingerprinting efforts by the attacker were unsuccessful, and high-quality deception was maintained. The reward per session for the RL agent ranges from + 0 to + 14.0 for different session types, resulting in the formation of a converged Q-table containing values of 21 out of 90 possible states. Additionally, the technique ensures the resistance against honeypot fingerprinting, and demonstrates resistance against evaluated fingerprinting attempts. As far as it is currently known, few previous works can be found which have managed to include explainable scoring, convergence of behavior analysis, adaptive control, environment mutation, and reinforcement learning into one cyber deception framework. The presented framework manages to incorporate all of these features while still preserving transparency and adaptability during the whole process of deception. The research makes advances in the current state-of-the-art research by enabling passive honeypots to become intelligent autonomous systems for detecting cyber threats.