An Approach to Detect and Classify Potentially Suspicious Activity from Real-Time Log Data using Anomaly Detection Methods

Arnab Sengupta, Akash Kundu, Aishi Mukhopadhyay · 2024

This paper aims to propose an intricate yet streamlined approach to incorporate Machine Learning into Cybersecurity by employing anomaly detection techniques to screen real-time log data and identify as well as classify suspicious activity. Our research focuses on avoiding misclassification with particular emphasis on minimising permissivity to ensure that threats with greater risk are not misclassified to a lesser priority. The paper explores a two-tiered strategy comprising an initial model dedicated to the identification of potentially suspicious log data through anomaly detection methods, serving as a preliminary filter. Subsequently, a secondary model is tasked with the responsibility of classifying the identified threats into distinct priority levels based on anomalous features. This approach sets groundwork for a robust framework that prioritises minimising vulnerability while maximising accuracy.

Read the paper · More papers on PaperTik