Machine Learning Detection and Categorization of Threats
Georgios Michailidis, Nikolaos Doukas, José Borges, Victor Selivanov · 2024
Tactical intelligence focuses on the near future, are technical in nature and are based on identifying simple Indicators of Compromise (IOCs). IOCs include malicious IP addresses, URLs, file hashes, and known malicious domain names. Tactical intelligence is a type of intelligence that is generated and almost always automated. As a result, it can be found through open-source and free data feeds, but it typically has a very short lifespan because IOCs can become obsolete within days or even hours. In tactical intelligence, Security Information and Event Management (SIEM), firewalls, endpoints, and IDSs/ Intrusion Prevention Systems (IPS) are involved. Network-based IDS (NIDS) which is involved in Tactical intelligence can be used for inspection of inbound and outbound traffic in order to identify specific patterns of malware or botnets communicating with command-and-control servers, Unauthorized Access Attempts as for breaching a network, such as repeated login attempts or brute-force attacks against network services and abnormal spikes in traffic with specific alerts as on ongoing DoS or Distributed Denial-of-Service (DDoS) attacks. In this paper a type of NIDS is proposed with the use of machine learning classification algorithms, such as the Random Forest Classifier, the Logistic Regression, KNeighbors Classifier, Light GBM, and XGBoost for classification of threats as malicious or not. Additionally, the classification of the subcategory of the cyberattacks as DoS, R2L, U2R and Probe is attempted.