Hybrid Machine Learning and Moving Target Defense (MTD) for Comprehensive Switchport Attack Detection
R. G. C. Upeksha, MWP Maduranga, NW Chanaka Lasantha, N.G.S. Aminda · 2024
This paper presents a multi-faceted framework to detect and forestall ARP poisoning attacks in switchport details enhanced by the MTD strategy incorporated with the real-time attack detection system DIPRM under dynamic IP randomization and managed by machine learning to counter new threats. The innovation of this work is the combination of dynamic IP randomization together with ML-based real-time attack detection that creates a strong defense strategy against ARP poisoning, the logical continuation of each static defense avert array, and making a point of the defensive-offensive balance typical for the old-fashioned static security systems. The proposed solution, if applied, exhibited a significant enhancement in addressing ARP poisoning attack identification and prevention aspects, as evinced by the findings on the UNSW-NB15, KDD’Cup99, and NSL-KDD datasets, where the receiver operating characteristic (ROC) curves of the selected hybrid models outperformed other single algorithmic approaches across precision, recall, and overall net accuracy lines. Consequently, the research study substantiates the efficacy of the discussed hybrid model for eliminating false positives and false negatives conducive to the stability and performance of the network without a significant decline in the system’s throughput.