Man-in-the-middle attacks are among the most dangerous types of cyber threats, which implies unauthorized interception of information exchange between two or more users. Real-time Identification of these attacks has been deemed particularly difficult because of the complexity of the data traffic and sometimes the overlap of the attack classes. In this work, we aim to improve the detection of these attacks based on the Machine Learning algorithm using the NSL-KDD dataset, a well-known dataset for applications in network intrusion detection. We use Possibilistic C-Means (PCM) clustering as the primary detection method. PCM clustering effectively handles uncertainty and overlapping clusters, making it well-suited for distinguishing Man-in-the-middle attacks from regular traffic. Thus, from this dataset, Chi-square and Information Gain feature selection methods are used to extract the attack features with the most distinguishing attributes. State experiments were performed with the help of an open-source software KNIME (Konstanz Information Miner), and several machine learning algorithms such as Naive Bayes Gaussian, SVM, SVM-SOM K-Means, Random Forest, and PCM clustering were tested. This paper proves that the proposed method, PCM clustering, outperforms other techniques in the actual positive rate and accuracy of identifying the attacks of its high detection rates and its enhanced handling of ambivalent data. This approach shows the strength of the PCM clustering for practical Man-in-the-middle attack detection and confirms the advantage of the proposed method over generic approaches.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Advancing Detection of Man-in-the-Middle Attacks Through Possibilistic C-Means Clustering

  • Saswati Chatterjee,
  • Lalmohan Pattnaik,
  • Suneeta Satpathy,
  • Deepthi Godavarthi

摘要

Man-in-the-middle attacks are among the most dangerous types of cyber threats, which implies unauthorized interception of information exchange between two or more users. Real-time Identification of these attacks has been deemed particularly difficult because of the complexity of the data traffic and sometimes the overlap of the attack classes. In this work, we aim to improve the detection of these attacks based on the Machine Learning algorithm using the NSL-KDD dataset, a well-known dataset for applications in network intrusion detection. We use Possibilistic C-Means (PCM) clustering as the primary detection method. PCM clustering effectively handles uncertainty and overlapping clusters, making it well-suited for distinguishing Man-in-the-middle attacks from regular traffic. Thus, from this dataset, Chi-square and Information Gain feature selection methods are used to extract the attack features with the most distinguishing attributes. State experiments were performed with the help of an open-source software KNIME (Konstanz Information Miner), and several machine learning algorithms such as Naive Bayes Gaussian, SVM, SVM-SOM K-Means, Random Forest, and PCM clustering were tested. This paper proves that the proposed method, PCM clustering, outperforms other techniques in the actual positive rate and accuracy of identifying the attacks of its high detection rates and its enhanced handling of ambivalent data. This approach shows the strength of the PCM clustering for practical Man-in-the-middle attack detection and confirms the advantage of the proposed method over generic approaches.