Forecasting Network Intrusions from Security Logs Using LSTMs

2Citations
Citations of this article
7Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Computer network intrusions are of increasing concern to governments, companies, and other institutions. While technologies such as Intrusion Detection Systems (IDS) are growing in sophistication and adoption, early warning of intrusion attempts could help cybersecurity practitioners put defenses in place early and mitigate the effects of cyberattacks. It is widely known that cyberattacks progress through stages, which suggests that forecasting network intrusions may be possible if we are able to identify certain precursors. Despite this potential, forecasting intrusions remains a difficult problem. By leveraging the rapidly growing and widely varying data available from network monitoring and Security Information and Event Management (SIEM) systems, as well as recent advances in deep learning, we introduce a novel intrusion forecasting application. Using six months of data from a real, large organization, we demonstrate that this provides improved intrusion forecasting accuracy compared to existing methods.

Cite

CITATION STYLE

APA

Mueller, W. G., Memory, A., & Bartrem, K. (2020). Forecasting Network Intrusions from Security Logs Using LSTMs. In Communications in Computer and Information Science (Vol. 1271 CCIS, pp. 122–137). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-030-59621-7_7

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free