Bài viết
Nền tảng phân loại tấn công mạng dựa vào mô hình Autoencoder và công nghệ phân tích luồng trực tuyến
- Nguyễn Việt Hùng (VN)
- Dang Thi Mai (VN)
- Ngo Thanh Tung (VN)
Tóm tắt
Tóm tắt— Để đối phó với các hình thức tấn công mạng đa dạng và thay đổi liên tục, các phương pháp học máy đã được nghiên cứu và áp dụng rộng rãi trong xử lý dữ liệu mạng để đạt được hiệu quả cao trong việc phát hiện tấn công mạng. Tuy nhiên, các mô hình học máy đòi hỏi tài nguyên tính toán lớn và việc áp dụng chúng để xử lý các vấn đề giám sát luồng dữ liệu thời gian thực vẫn cần được cải thiện. Trong bài báo này, chúng tôi nghiên cứu và đề xuất mô hình phát hiện tấn công mạng sử dụng thuật toán phân lớp 2 giai đoạn kết hợp với mạng Autoencoder, tích hợp công nghệ xử lý luồng dữ liệu trực tuyến dựa trên Apache Kafka và Apache Spark. Kết quả cho thấy rằng mô hình được đề xuất có hiệu suất cao trong việc phát hiện tấn công mạng và thời gian xử lý nhanh hơn so với công nghệ xử lý dữ liệu truyền thống.
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Nguyễn Việt Hùng, Dang Thi Mai, Ngo Thanh Tung (2023). Nền tảng phân loại tấn công mạng dựa vào mô hình Autoencoder và công nghệ phân tích luồng trực tuyến. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 1(18), 3-19. https://doi.org/10.54654/isj.v1i18.938
Tài liệu tham khảo
- 1.A. Chidukwani, S. Zander and P. Koutsakis, “A Survey on the Cyber Security of Small-to-Medium Businesses: Challenges, Research Focus and Recommendations,” in IEEE Access, vol. 10, pp. 85701-85719, 2022, doi: 10.1109/ACCESS.2022.3197899.
- 2.A. Halbouni, T. S. Gunawan, M. H. Habaebi, M. Halbouni, M. Kartiwi and R. Ahmad, “Machine Learning and Deep Learning Approaches for CyberSecurity: A Review,” in IEEE Access, vol. 10, pp. 19572-19585, 2022, doi: 10.1109/ACCESS.2022.3151248.
- 3.R. P. Krupani, M. G. Aditya, C. S. Prithvi Raghavan and H. S. Gururaja, “Big Data Cybersecurity Monitoring System using Machine Learning,” 2021 International Conference on Forensics, Analytics, Big Data, Security (FABS), Bengaluru, India, 2021, pp. 1-7, doi: 10.1109/FABS52071.2021.9702637.
- 4.Clay. P. - “A modern threat response framework”, Network Security, v.2015, n. 4, pp. 5(October 2015).
- 5.IBM report - “Cost of a data breach 2022” - https://www.ibm.com/reports/data-breach - Last Visited: 7/3/2023.
- 6.COLUCCIO, R., Ghidini, G., REALE, A., et al. “Online stream processing of machine-to-machine communications traffic: A platform comparison”. In: IEEE Symposium on Computers and Communication (ISCC), pp. 1{7, 6 2014. doi: 10.1109/ISCC.2014.6912528.
- 7.Hu P., Li, H., Fu, H., et al. “Dynamic defense strategy against advanced persistent threat with insiders.” In: 2015 IEEE Conference on Computer Communications (INFOCOM), pp. 747.
- 8.Paxson V. “Bro: a system for detecting network intruders in real-time”, Computer Networks, v. 31, n. 23-24, pp. 2435.
- 9.Bar A., Finamore A., Casas, P., et al. “Large-scale network traffic monitoring with DBStream, a system for rolling big data analysis.” In: 2014 IEEE International Conference on Big Data (Big Data), pp. 165{170. IEEE, 10 2014. ISBN: 978-1- 4799-5666-1. doi: 10.1109/BigData.2014.7004227.
- 10.Stonebraker M.,Etintemel U., Zdonik, S. “The 8 requirements of real-time stream processing”, ACM SIGMOD Record, v. 34, n. 4, pp. 42{ 47, 12 2005. ISSN: 01635808. doi : 10.1145/1107499.1107504.
- 11.S plunk Buys Another Startup, Launches Mission Control - https://www.sdxcentral.com/articles/news/splunk-buys-another-startup-launches-mission-control/2019/10/ - Last Accessed 6/7 2020.
- 12.Dimensionality reduction for machine learning based iot botnet detection, H. Bahsi, S. Nomm, and FBL Torre, in 15th International Conference on Control, Automation, Robotics and Vision, ICARCV 2018, Singapore, November 18-21 , 2018, pp . 1857-1862.
- 13.Unsupervised anomaly based botnet detection in iot networks, S. Nomm and H. Bahsi, in 17th IEEE International Conference on Machine Learning and Applications, ICMLA 2018, Orlando, FL, USA, December 17-20, 2018, 2018, pp. 1048–1053.
- 14.G. Pang, C. Shen, L. Cao, and A. Van Den Hengel, “Deep Learning for Anomaly Detection: A Review,” ACM Computing Surveys, vol. 54, no. 2. Association for Computing Machinery, Apr. 01, 2021, doi: 10.1145/3439950.
- 15.R. Kumar and R. Verma, (2012), “Classification algorithms for data mining: A survey”, International Journal of Innovations in Engineering and Technology (IJIET), [7-14].
- 16.Adnan Mohsin Abdulazeez, (2021), “Classification Based on Decision Tree Algorithm for Machine Learning”, Journal of Applied Science and Technology Trends.
- 17.Dianne SV Medeiros; Helio N. Cunha Neto; Martin Andreoni Lopez, (2020), “A survey on data analysis on large-Scale wireless networks: online stream processing, trends, and challenges”, Journal of Internet Services and Applications.
- 18.Haruna Isah; Tariq Abughofa; Sazia Mahfuz; Dharmitha Ajerla; Farhana Zulkernine; Shahzad Khan, (2019), “A Survey of Distributed Data Stream Processing Frameworks”, IEEE Access, 7, 154300 – 154316.
- 19.Meijuan Gao, Jingwen Tian, Mingping Xia, Intrusion Detection Method Based on Classify Support Vector Machine , secondInternational Conference on Intelligent Computation Technology and Automation, ICICTA ’09, vol. 2, pp. 391-394.
- 20.BHUYAN, Monowar H.; BHATTACHARYYA, Dhruba K.; KALITA, Jugal K, AOCD: An Adaptive Outlier Based Coordinated Scan Detection Approach , IJ Network Security, 2012, 14.6: 339-351.
- 21.Chao Wang, Bailing Wang, Hongri Liu, Haikuo, Anomaly Detection for Industrial Control System Based on Autoencoder Neural Network, 2020, Wireless Communications and Mobile Computing.
- 22.Nguyen Viet Hung, Nguyen Van Quan, Le Thi Trang Linh, Shone Nathan, (2018), “Using Deep Learning Model for Network Scanning Detection”, ICFET ‘18: Proceedings of the 4th International Conference on Frontiers of Educational Technologies , [117-121].
- 23.Xavier Glorot, Yoshua Bengio, (2010), “Understanding the difficulty of training deep feedforward neural networks”, Journal of Machine Learning Research 9, [249-256].
- 24.JIRSIK, T., CERMAK, M., TOVARNAK, D., et al. “Toward Stream-Based IP
- 25.Flow Analysis”, IEEE Communications Magazine, v. 55, n. 7, pp. 70-76,
- 26.ISSN: 0163-6804. doi: 10.1109/MCOM.2017.1600972.
Bài viết liên quan
- Phát triển Framework ứng dụng AI hỗ trợ tự động khai thác lỗ hổng bảo mật
- Applying reinforcement learning in automated penetration testing
- Tự động chọn hàm bị loại bỏ trong kiểm thử bản vá khi sử dụng Thực thi tượng trưng lược bớt
- Ứng dụng mô hình học sâu trong phát hiện tấn công trinh sát mạng
- Nâng cao hiệu quả phát hiện mã độc của mô hình deeplearning với phương pháp biểu diễn ảnh mới
- Nâng cao hiệu quả mô hình học máy trong phát hiện tấn công lừa đảo website sử dụng đặc điểm hình thái trong phân tích URL