Location

Hilton Waikoloa Village, Hawaii

Event Website

https://hicss.hawaii.edu/

Start Date

7-1-2025 12:00 AM

End Date

10-1-2025 12:00 AM

Description

Network intrusion detection systems (NIDS) are pivotal in cybersecurity operations centers (CSOCs) for detecting malicious activities. While signature-based NIDS rely on predefined rules, anomaly-based NIDS utilize machine learning (ML) and deep learning (DL) to detect anomalies. However, these models face challenges such as susceptibility to evasion attacks and high false positives and negatives. This study proposes a novel defense framework integrating supervised and unsupervised learning paradigms to enhance NIDS capabilities. The framework accurately identifies known attacks, detects adversarial attacks and their toolchains, and distinguishes novel attacks. Experimental evaluations on benchmark network intrusion data sets demonstrate high detection accuracies. Motivated by the need to attribute attacks and understand adversary motivations, the framework includes a toolchain detection component, crucial for developing comprehensive threat intelligence and improving incident response in CSOCs.

Share

COinS
 
Jan 7th, 12:00 AM Jan 10th, 12:00 AM

Towards Attribution in Network Attacks: A Deep Learning-Based Robust Framework for Intrusion Detection and Adversarial Toolchain Identification

Hilton Waikoloa Village, Hawaii

Network intrusion detection systems (NIDS) are pivotal in cybersecurity operations centers (CSOCs) for detecting malicious activities. While signature-based NIDS rely on predefined rules, anomaly-based NIDS utilize machine learning (ML) and deep learning (DL) to detect anomalies. However, these models face challenges such as susceptibility to evasion attacks and high false positives and negatives. This study proposes a novel defense framework integrating supervised and unsupervised learning paradigms to enhance NIDS capabilities. The framework accurately identifies known attacks, detects adversarial attacks and their toolchains, and distinguishes novel attacks. Experimental evaluations on benchmark network intrusion data sets demonstrate high detection accuracies. Motivated by the need to attribute attacks and understand adversary motivations, the framework includes a toolchain detection component, crucial for developing comprehensive threat intelligence and improving incident response in CSOCs.

https://aisel.aisnet.org/hicss-58/cl/security/2