Machine Learning for Enterprise Security: Detecting Kerberos-Based Attacks Using UNSW-NB15 Dataset
Jigar A. Soni, Aditya Vairavan, Ravikumar B Panchal ., Himanshu Patel, Rajan B. Patel · JOURNAL OF EMERGING TRENDS AND NOVEL RESEARCH · 2025
Golden Ticket and Kerberoasting are a couple of Kerberos-based attacks that significantly undermine enterprise network security and require advanced detection methods. Challenges persist with using machine learning (ML)-based intrusion detection methods for specific protocols, e.g., Kerberos, and satisfying the practical deployment needs in security operations centers (SOCs) in spite of the progress made in this area. This work compares Random Forest, Isolation Forest, Long Short-Term Memory (LSTM), and XGBoost for detecting such threats based on the UNSW-NB15 dataset. The respective accuracies are 0.9585, 0.3225, 0.9585, and 0.9585. To improve interpretability and practical applicability, we suggest a hybrid model that combines Random Forest and rule-based filtering. With solving interpretability and deployment gaps and adapting UNSW-NB15 for Kerberos detection, the research fills the gaps between theoretical developments and SOC demands and presents a systematic framework for business security.