Location
Hilton Waikoloa Village, Hawaii
Event Website
https://hicss.hawaii.edu/
Start Date
7-1-2025 12:00 AM
End Date
10-1-2025 12:00 AM
Description
Network intrusion detection systems (NIDS) are pivotal in cybersecurity operations centers (CSOCs) for detecting malicious activities. While signature-based NIDS rely on predefined rules, anomaly-based NIDS utilize machine learning (ML) and deep learning (DL) to detect anomalies. However, these models face challenges such as susceptibility to evasion attacks and high false positives and negatives. This study proposes a novel defense framework integrating supervised and unsupervised learning paradigms to enhance NIDS capabilities. The framework accurately identifies known attacks, detects adversarial attacks and their toolchains, and distinguishes novel attacks. Experimental evaluations on benchmark network intrusion data sets demonstrate high detection accuracies. Motivated by the need to attribute attacks and understand adversary motivations, the framework includes a toolchain detection component, crucial for developing comprehensive threat intelligence and improving incident response in CSOCs.
Recommended Citation
Bakht, Ahtesham; Shah, Ankit; and Bastian, Nathaniel, "Towards Attribution in Network Attacks: A Deep Learning-Based Robust Framework for Intrusion Detection and Adversarial Toolchain Identification" (2025). Hawaii International Conference on System Sciences 2025 (HICSS-58). 2.
https://aisel.aisnet.org/hicss-58/cl/security/2
Towards Attribution in Network Attacks: A Deep Learning-Based Robust Framework for Intrusion Detection and Adversarial Toolchain Identification
Hilton Waikoloa Village, Hawaii
Network intrusion detection systems (NIDS) are pivotal in cybersecurity operations centers (CSOCs) for detecting malicious activities. While signature-based NIDS rely on predefined rules, anomaly-based NIDS utilize machine learning (ML) and deep learning (DL) to detect anomalies. However, these models face challenges such as susceptibility to evasion attacks and high false positives and negatives. This study proposes a novel defense framework integrating supervised and unsupervised learning paradigms to enhance NIDS capabilities. The framework accurately identifies known attacks, detects adversarial attacks and their toolchains, and distinguishes novel attacks. Experimental evaluations on benchmark network intrusion data sets demonstrate high detection accuracies. Motivated by the need to attribute attacks and understand adversary motivations, the framework includes a toolchain detection component, crucial for developing comprehensive threat intelligence and improving incident response in CSOCs.
https://aisel.aisnet.org/hicss-58/cl/security/2