Cybersecurity has been a volatile and growing issue in using the Internet for business, communications, marketing, and social presence, for over 30 years, requiring constant alert protection from cyber-attacks. That is why it is important for all our systems to develop and implement good monitoring tools, which can detect data breaches and other forms of cyber-attacks from threat actors in near real time. Adversaries attack mostly from the Dark Web because it is the only web layer where users can act anonymously. However not all Distributed Denial of Service (DDoS), ransomware, botnet, and other attack types are performed through the Dark Web. That is why we need a monitoring system, which can detect all attack types from various online locations. In this paper we present a simple experimental approach with the use of appropriate Machine Learning (ML) techniques to detect attacks from network packets, which are grabbed via NetworkMiner. We used the Weka Framework to perform our monitoring actions in near real time. The authors deliberately chose the Weka Framework, a freeware tool with ML techniques to detect anomalies, which can be used by Small and Medium Enterprises (SMEs) quite efficiently to monitor illegal activities. NetworkMiner can also be used as freeware, but if an SME needs more details about network packets, then it costs almost $US1000. These two tools can be combined to provide an efficient low-cost entry level way to monitor a network system as the SME migrates towards the “near real-time detection” state where.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Near Realtime Attack Detections with Weka Framework

  • Selahattin Hürol Türen,
  • Kenneth Eustace,
  • Rafiqul Islam,
  • Geoffrey Fellows

摘要

Cybersecurity has been a volatile and growing issue in using the Internet for business, communications, marketing, and social presence, for over 30 years, requiring constant alert protection from cyber-attacks. That is why it is important for all our systems to develop and implement good monitoring tools, which can detect data breaches and other forms of cyber-attacks from threat actors in near real time. Adversaries attack mostly from the Dark Web because it is the only web layer where users can act anonymously. However not all Distributed Denial of Service (DDoS), ransomware, botnet, and other attack types are performed through the Dark Web. That is why we need a monitoring system, which can detect all attack types from various online locations. In this paper we present a simple experimental approach with the use of appropriate Machine Learning (ML) techniques to detect attacks from network packets, which are grabbed via NetworkMiner. We used the Weka Framework to perform our monitoring actions in near real time. The authors deliberately chose the Weka Framework, a freeware tool with ML techniques to detect anomalies, which can be used by Small and Medium Enterprises (SMEs) quite efficiently to monitor illegal activities. NetworkMiner can also be used as freeware, but if an SME needs more details about network packets, then it costs almost $US1000. These two tools can be combined to provide an efficient low-cost entry level way to monitor a network system as the SME migrates towards the “near real-time detection” state where.