The cyber security concerns are increasing in both volume and complexity as cyber warfare elevates to new levels across global actors. This research paper presents a partial ML model which comprises of Logistic Regression as well as Support Vector Machines in order to enhance the identification as well as the categorization of cyber threats. The model is tested on a data set that comprise of a variety of attacks namely, Denial of Service (DoS), SQL Injection, phishing, and Man-in-the-middle attacks. An autoencoder, a type of artificial neural network, is used for classifying agents in the early stages, thereby acting as an anomaly detection technique, which is capable of identifying patterns that deviate from normal network activity. This preprocessing stage also allows the hybrid model to perform the classification of the described attacks much more quickly. The moderate reliance on LR in binary classification combined with the high reliance on SVM in hyper-dimensional spaces proves advantageous in detecting targeted cyber threats. Such attacks included SQL Injection and Phishing. The hybrid model recorded a general accuracy of 94 percentages in its application along with improved precision and recall for target attack classes. The objective of the paper is to use hybrid machine learning methods to achieve the necessary time and accuracy parameters for the deployment of the ML system in real-time cybersecurity systems. The system architecture is designed so that the false positive rate may be reduced and the robustness of the security systems may be enhanced. This study furthers the development of the sector in question by demonstrating that hybrid models are superior to traditional single-model design in terms of detecting and classifying threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Real-Time Security Monitoring: A Hybrid Machine Learning Approach to Cyber Threat Detection

  • Vinoth Kumar Kolluru,
  • Yagnesh Challagundla,
  • Sudeep Mungara,
  • Advaitha Naidu Chintakunta,
  • Siddhartha Nuthakki,
  • Kritika Bansal

摘要

The cyber security concerns are increasing in both volume and complexity as cyber warfare elevates to new levels across global actors. This research paper presents a partial ML model which comprises of Logistic Regression as well as Support Vector Machines in order to enhance the identification as well as the categorization of cyber threats. The model is tested on a data set that comprise of a variety of attacks namely, Denial of Service (DoS), SQL Injection, phishing, and Man-in-the-middle attacks. An autoencoder, a type of artificial neural network, is used for classifying agents in the early stages, thereby acting as an anomaly detection technique, which is capable of identifying patterns that deviate from normal network activity. This preprocessing stage also allows the hybrid model to perform the classification of the described attacks much more quickly. The moderate reliance on LR in binary classification combined with the high reliance on SVM in hyper-dimensional spaces proves advantageous in detecting targeted cyber threats. Such attacks included SQL Injection and Phishing. The hybrid model recorded a general accuracy of 94 percentages in its application along with improved precision and recall for target attack classes. The objective of the paper is to use hybrid machine learning methods to achieve the necessary time and accuracy parameters for the deployment of the ML system in real-time cybersecurity systems. The system architecture is designed so that the false positive rate may be reduced and the robustness of the security systems may be enhanced. This study furthers the development of the sector in question by demonstrating that hybrid models are superior to traditional single-model design in terms of detecting and classifying threats.