Identifying Zero-Day Attacks with Machine Learning and Data Reduction Methods
Haydar Teymourlouei, Daryl Stone, Lethia Jackson · 2023
Understanding the threats affecting your network is essential to developing a successful cyber-security defense. One threat that is crucial to building a defense against is a zero-day attack. The problem is that a zero-day attack leaves one with no real way to prepare for the attack other than searching through logs and logs of system logs looking for anomalies in the data. Recently, machine learning (ML) has been proposed to handle big data streams such as these. We compare two methods: a common data reduction algorithm that reduces the number of attributes in a dataset while keeping as much variation in the original dataset as possible. The second method will be focused on developing ML algorithms using deep learning with the Stochastic gradient descent (SGD) classified legitimate traffic that is referred to as a true-positive. The results of the first method showed a 500% reduction in data removed many of the events considered to be zero-day threats. Further, the performance of the second method exceeded 97% accuracy. These results suggest the methods presented here are effective in the identification of zero-day attacks. To validate these results, further testing should be done.