Due to the increase in Internet usage, there has been a significant rise in malicious activities, necessitating watchful monitoring of Internet traffic to ensure data security. This paper introduces the development of a novel two-stage Intrusion Detection System (IDS) utilizing XGBoost (XGB) and Random Forest (RF). XGBoost is used for the detection of FTP and SSH brute force attack identification, infiltration and SQL injection detection, while Random Forest is used to detect Exploits, Worms, Shellcodes and Backdoors. Importantly, the system prioritizes user privacy and adheres to stringent security protocols. The system also achieves notable accuracies of 95.50% for network-based attack classification and 98.81% for malware-based attack detection. This approach overcomes limitations associated with relying on a single dataset by incorporating specialized datasets tailored to specific attack types. This combined network-based attack classification and malware-based attack detection presents itself as a solution for strengthening web and system security in the face of evolving cyber threats.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Bakshi: Elevating Cybersecurity with a Two-Stage Multi-class Classification for Malware and Network Intrusion Detection

  • S. Sanjana,
  • Sneha Srinivasan,
  • V. Bavanika,
  • Sameeraa Prinakaa,
  • V. Sarasvathi

摘要

Due to the increase in Internet usage, there has been a significant rise in malicious activities, necessitating watchful monitoring of Internet traffic to ensure data security. This paper introduces the development of a novel two-stage Intrusion Detection System (IDS) utilizing XGBoost (XGB) and Random Forest (RF). XGBoost is used for the detection of FTP and SSH brute force attack identification, infiltration and SQL injection detection, while Random Forest is used to detect Exploits, Worms, Shellcodes and Backdoors. Importantly, the system prioritizes user privacy and adheres to stringent security protocols. The system also achieves notable accuracies of 95.50% for network-based attack classification and 98.81% for malware-based attack detection. This approach overcomes limitations associated with relying on a single dataset by incorporating specialized datasets tailored to specific attack types. This combined network-based attack classification and malware-based attack detection presents itself as a solution for strengthening web and system security in the face of evolving cyber threats.