Machine Learning based Early Detection of Ongoing Cyber-Attacks

A Bhagyalakshmi, C D Sruthi Laya, A M Yoga Preethikaa, V Varsha · 2024

The need for sophisticated detection and response systems to counteract cyber threats has grown in importance as the cybersecurity landscape changes. In order to improve cyberattack detection and response, this study proposes a novel combination of a Security Orchestration, Automation, and Response (SOAR) framework with a machine learning (ML) model. A Random Forest classifier was created and trained to distinguish between benign and potentially dangerous files using a dataset that included a variety of executable file properties. The classifier demonstrated a notable level of accuracy and precision. Then, a prediction API was established to enable real-time threat analysis by seamlessly integrating the learned machine learning model into a SOAR system. Through this integration, possible threats can be continuously identified by evaluating real-time data that has been retrieved from network traffic and endpoints. The SOAR system is activated when a suspicious file is found, which sets off a sequence of automatic events that include notifying security staff and starting response procedures. For a comprehensive and strong defence strategy, the system also integrates with already-in-use security solutions like firewalls and intrusion detection systems (IDS). The integration strengthens the overall cybersecurity posture by improving response time and increasing the effectiveness of cyberattack detection. This study presents the integrated approach’s methodology, system architecture, and effectiveness, showcasing its potential as a $comprehensive$ cybersecurity solution.

Read the paper · More papers on PaperTik