Detection of Distributed Cyber Attacks Based on Weighted Ensembles of Classifiers and Big Data Processing Architecture

Igor Vitalievich Kotenko, Igor Borisovich Saenko, Alexander Alexanderovich Branitskiy · 2019

Distributed cyber attacks represent a special class of attacks on computer networks and systems which is rather difficult to detect. In many respects it is explained by the complexity of such detection demanding joint implementation of procedures of data analysis and technologies of Big Data processing. For this reason the development of new methods for detection of distributed cyber attacks is of great interest to specialists in the field of cyber security. The paper offers a new approach to detection of such cyber attacks. The approach is based on sharing of the weighted ensembles of different classifiers (Decision trees, Logistic regression, Support vector machines) and the Big Data processing architecture. Results of comparative analysis of three different types of the weighted ensembles (weighted voting, soft voting, and adaboost) integrating basic classifiers are evaluated. Experiments, made with use of the CICIDS2017 data set, demonstrated a rather high effectiveness of cyber attack detection and the acceptable level of consumption of the system and time resources. The approach suggested can be used for other related information assurance tasks, for example, detection and counteraction of inappropriate, dubious and harmful information.

Read the paper · More papers on PaperTik