Generating a benchmark cyber multi-step attacks dataset for intrusion detection

Author:

Almseidin Mohammad1,Al-Sawwa Jamil2,Alkasassbeh Mouhammd3

Affiliation:

1. Computer Science Department, Aqaba University of Technology, Aqaba, Jordan

2. Computer Science Department, Tafila Technical University, Tafila, Jordan

3. Computer Science Department, Princess Sumaya University for Technology, Amman, Jordan

Abstract

Nowadays, with the rapid increase in the number of applications and networks, the number of cyber multi-step attacks has been increasing exponentially. Thus, the need for a reliable and acceptable Intrusion Detection System (IDS) solution is becoming urgent to protect the networks and devices. However, implementing a robust IDS needs a reliable and up-to-date dataset in order to capture the behaviors of the new types of attacks especially a multi-step attack. In this paper, a new benchmark Multi-Step Cyber-Attack Dataset (MSCAD) is introduced. MSCAD includes two multi-step scenarios; the first scenario is a password cracking attack, and the second attack scenario is a volume-based Distributed Denial of Service (DDoS) attack. The MSCAD was assessed in two manners; firstly, the MSCAD was used to train IDS. Then, the performance of IDS was evaluated in terms of G-mean and Area Under Curve (AUC). Secondly, the MSCAD was compared with other free open-source and public datasets based on the latest keys criteria of a dataset evaluation framework. The results show that IDS-based MSCAD achieved the best performance with G-mean 0.83 and obtained good accuracy to detect the attacks. Besides, the MSCAD successfully passing twelve keys criteria.

Publisher

IOS Press

Subject

Artificial Intelligence,General Engineering,Statistics and Probability

Reference27 articles.

1. Fuzzy automaton as a detection mechanism for the multi-step attack;Mohammad Almseidin;International Journal on Advanced Science, Engineering and Information Technology

2. A multi-step attack recognition and prediction method via mining attacks conversion frequencies;Da-peng;Int J Wirel Microw Technol (IJWMT),2012

3. Shigen Shen , Keli Hu , Longjun Huang , Hongjie Li , Risheng Han and Qiying Cao , Quantal response equilibrium-based strategies for intrusion detection in wsns, , Mobile Information Systems 2015 (2015).

4. Yanxue Zhang , Dongmei Zhao and Jinxing Liu , The application of baum-welch algorithm in multistep attack, , The Scientific World Journal 2014 (2014).

5. Detection of iot-botnet attacks using fuzzy rule interpolation;Mouhammd Al-Kasassbeh;Journal of Intelligent & Fuzzy Systems,2020

Cited by 8 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. DT-ARO: Decision Tree-Based Artificial Rabbits Optimization to Mitigate IoT Botnet Exploitation;Journal of Network and Systems Management;2023-12-07

2. Pythagorean Fuzzy Sets-based VIKOR and TOPSIS-based multi-criteria decision-making model for mitigating resource deletion attacks in WSNs;Journal of Intelligent & Fuzzy Systems;2023-06-01

3. Towards Intelligent Attack Detection Using DNA Computing;ACM Transactions on Multimedia Computing, Communications, and Applications;2023-02-24

4. Attention-based RNN architecture for detecting multi-step cyber-attack using PSO metaheuristic;2023 International Conference on Electrical, Computer and Communication Engineering (ECCE);2023-02-23

5. Rule-based Intrusion Detection System using Logical Analysis of Data;2023 International Conference on Intelligent Data Communication Technologies and Internet of Things (IDCIoT);2023-01-05

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3