Autonomous Threat Detection and Response for Self-Protected Networks
Wessel Havenga, Antoine Bagula, Olasupo O. Ajayi · 2022
Cyber security defence tools and methodologies constantly contend with ever evolving, highly intelligent new generation of threats. The main challenges posed by these modern digital multi-vector attacks is their ability to adapt. Research shows that many existing defence systems fail to provide adequate protection against these latest threats. Hence, there is an ever-growing need for self-learning defence technologies that can autonomously adjust to the behavioural patterns of malicious actors. The accuracy and effectiveness of existing defence mechanisms depend on the decisions and manual input of human expert. This dependence results in administrative overheads, inconsistencies, errors, and delayed response time. This paper proposes an Autonomous Threat Detection and Response (ATDR) system which combines unsupervised machine learning, for autonomous threat detection, with intelligent queue management for an effective self-organized responses to threats. Results of conducted experiments show that ATDR can accurately classify network traffic in real time based on pattern and effectively isolate malicious traffic flow with minimal delay to the traffic flow. The use of round-robin to manage the scheduling helps reduce wait time, but with a marginal increase in re-scheduling frequency.