Zero-day attacks exploit previously unknown vulnerabilities and pose a significant cybersecurity threat. Traditional signature-based detection methods struggle against these attacks due to their lack of prior knowledge about attack patterns. This paper investigates the potential of Proximal Policy Optimization (PPO), a reinforcement learning (RL) technique, for zero-day attack detection. The growing sophistication of zero-day attacks often employing advanced techniques and malware necessitates novel detection approaches. We focus on PPO due to its ability to learn optimal policies for taking actions based on observed network traffic data. This capability aligns well with the need to adapt to unseen attack patterns in real-time. This research explores the application of PPO in a simulated network environment, aiming to train an agent that can effectively identify and respond to zero-day attacks. By leveraging PPO’s ability to learn and adapt to dynamic threat landscapes, the proposed approach offers a promising avenue for mitigating zero-day attack risks. The research demonstrates the potential of PPO model in detection of zero-day attacks, achieving a significant improvement over traditional methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Real-Time Zero-Day Attack Detection with Proximal Policy Optimization

  • Premanand Ghadekar,
  • Harshita Bhagat,
  • Parth More,
  • Chinmay Saraf,
  • Vaishali More,
  • Sarthak Khare

摘要

Zero-day attacks exploit previously unknown vulnerabilities and pose a significant cybersecurity threat. Traditional signature-based detection methods struggle against these attacks due to their lack of prior knowledge about attack patterns. This paper investigates the potential of Proximal Policy Optimization (PPO), a reinforcement learning (RL) technique, for zero-day attack detection. The growing sophistication of zero-day attacks often employing advanced techniques and malware necessitates novel detection approaches. We focus on PPO due to its ability to learn optimal policies for taking actions based on observed network traffic data. This capability aligns well with the need to adapt to unseen attack patterns in real-time. This research explores the application of PPO in a simulated network environment, aiming to train an agent that can effectively identify and respond to zero-day attacks. By leveraging PPO’s ability to learn and adapt to dynamic threat landscapes, the proposed approach offers a promising avenue for mitigating zero-day attack risks. The research demonstrates the potential of PPO model in detection of zero-day attacks, achieving a significant improvement over traditional methods.