An Ensemble Learning for Multi-step Cyberattack Detection in IoT Framework by OverSampling of Minority Instances
摘要
The realm of cybersecurity places significant emphasis on researching the IoT. This focus arises from the growing reliance on automated devices and the limitations of general-purpose IDS when applied to specialized network contexts. In the contemporary landscape, attackers often follow a series of intrusion steps to achieve their ultimate goal. This sequence of steps is referred to as a multi-step attack scenario. The complexity of these multi-step attacks poses challenges for intrusion detection, as it requires the correlation of multiple actions to comprehend the attack strategy and recognize the associated threat. Multi-step attacks are inherently biased based on category of cyberattacks characterized by their complexity and the fact that they involve multiple stages or actions. The bias of attack instances come from the attackers themselves, who may target specific vulnerabilities or focus on objectives based on their motivations and goals. However, to the best of the authors’ knowledge, there are currently few available IDS datasets containing instances of multi-step benign activity. This chapter addresses this gap by assessing the effectiveness of ensembles techniques through oversampling-based in detecting multi-step-based attacks. To facilitate this research, a MSCAD is employed for training and evaluation purposes.