An Advanced Approach for Detecting Behavior-Based Intranet Attacks by Machine Learning

2Citations
Citations of this article
47Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

To address continuously increasing cyber threats, security professionals within organizations are fortifying internal security by implementing security policies such as network segregation and emerging concepts such as Zero Trust. However, despite these changes in the cybersecurity landscape, the ultimate goal of cyber attackers, which is to exfiltrate critical information stored within an organization's intranet, remains unchanged. Consequently, attackers with motives such as hacktivists persistently and repeatedly target key systems within an organization's intranet to achieve their ultimate objectives. Considering the tendencies of intranet attackers, this study proposes the inclusion of the number of connection attempts for attack detection as an additional attribute alongside commonly used attributes such as source IP, destination IP, protocol, and attack signatures in intrusion detection rules. This proposal is supported by establishing an experimental environment for conducting intranet attacks and collecting raw data. Using feature engineering techniques, the raw data were transformed into analyzable datasets, and the performance was measured using six supervised machine learning algorithms. Through this research, we aim to contribute to the field of cybersecurity by going beyond the conventional focus on Internet-based attacks and providing a methodology for analyzing various intranet-based attacks in a post-stage environment. In addition, we share the method of feature engineering Zeek IDS raw data and release the resulting dataset to further advance the field. We hope that these contributions will foster future developments in this domain.

References Powered by Scopus

The Problem of Overfitting

2023Citations
N/AReaders
Get full text

On hyperparameter optimization of machine learning algorithms: Theory and practice

1885Citations
N/AReaders
Get full text

Logistic regression and artificial neural network classification models: A methodology review

1686Citations
N/AReaders
Get full text

Cited by Powered by Scopus

Enhanced Hybrid Approach for Multi-Class DDoS Attack Detection and Classification in Software-Defined Networks Using Remote Sensing and Data Analytics

0Citations
N/AReaders
Get full text

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Cite

CITATION STYLE

APA

Jang, M., & Lee, K. (2024). An Advanced Approach for Detecting Behavior-Based Intranet Attacks by Machine Learning. IEEE Access, 12, 52480–52495. https://doi.org/10.1109/ACCESS.2024.3387016

Readers over time

‘24‘2509182736

Readers' Seniority

Tooltip

PhD / Post grad / Masters / Doc 7

54%

Researcher 4

31%

Lecturer / Post doc 2

15%

Readers' Discipline

Tooltip

Engineering 5

38%

Computer Science 4

31%

Biochemistry, Genetics and Molecular Bi... 4

31%

Article Metrics

Tooltip
Mentions
News Mentions: 1

Save time finding and organizing research with Mendeley

Sign up for free
0