Realtime Cyber Threat Dataset Generator Over PRBS Block Circuit
Saiyed Rasol bin Tuan Muda, Mohammad Hafiz Mohd Yusof, Radzi Ikhsan Ahmad · 2022
Realistic dataset is crucial to assist the development of advanced IDS classifier models. However, the available public IDS dataset has long been criticized of its impracticality to render real time cyber threats. Hence tapping into live network would be a relevant and interesting option. However, it is very unlikely any Telco will allow this to happen due to various business and data security reasons. Thus, the ultimate source of dataset to be studied are from any public domain logged traffic datasets. Pseudo Random Binary Sequence (PRBS) is manmade random signal, which may be an alternative candidate to help in identifying threat in traffic dataset. This paper is exploring the possibility of using PRBS in cyber security mitigation. It starts with designing and testing a few electronic circuits 1)a 127bitsPRBS generator, 2) a 127th bit decoder, 3) a 7bits PRBS generator, 4) a multiplexer and 5) a matched filter in the form of a correlator. The circuits are connected to function as a mini simulation laboratory that generate synthetic composite traffic dataset with threat. The simulation is to examine if matched filter and correlation method can help with threat detection in traffic data. As expected for known static datasets it is possible to detect data and threat signals using simple match filtering. What about the real dynamically random datasets that are unknown to us whether threats exist or not. These results suggest that if the local PRBS generator is designed to be adaptive (or put into hunting mode) towards incoming unknown dataset then the same correlation technique should be able to detect and separate actual traffic data from the threat data signals. This is where AI with deep learning stands a chance to make the PRBS block adaptive to the incoming traffic.