使用Splunk机器学习工具包检测和分类网络攻击

D. Satybaldina, N.K. Bisenbaeva, Y. Seitkulov, A.K. Seksenbaeva
{"title":"使用Splunk机器学习工具包检测和分类网络攻击","authors":"D. Satybaldina, N.K. Bisenbaeva, Y. Seitkulov, A.K. Seksenbaeva","doi":"10.32523/2616-7182/bulmathenu.2023/1.2","DOIUrl":null,"url":null,"abstract":"In modern conditions of digital technologies implementation in various sectors of the economy, the digitalization of public administration, healthcare, education, and science, the growth in the number of Internet services and mobile devices the issues of ensuring the security of cellular communication systems are becoming increasingly relevant. It is becoming increasingly difficult to detect multiple and complex cyber security threats as the sources and methods ofcyber-attacks evolve and expand. Classic network attack detection approaches that rely heavily on static matching, such as signature analysis, blacklisting, or regular expression patterns, are limited in flexibility and are ineffective for early anomaly detection and rapid response to information security incidents. To solve this problem, the use of machine learning (ML) algorithms is proposed. ML methods can provide new approaches and higher rates of detection of malicious activity on the network. In this work, the Splunk Enterprise data analysis platform and the Splunk Machine Learning Toolkit for creating, training, testing, and validating a network attack classifier are used. The performance of the proposed model was evaluatedby applying four machine learning algorithms such as a decision tree, a support vector machine, a random forest, and adouble random forest. Experimental results show that all used ML algorithms can be effectively used to detect network attacks, and the double random forest method has the best accuracy in detecting distributed denial-of-service attacks.","PeriodicalId":286555,"journal":{"name":"BULLETIN of the L N Gumilyov Eurasian National University MATHEMATICS COMPUTER SCIENCE MECHANICS Series","volume":"113 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-03-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Detecting and classifying network attacks with Splunk Machine Learning Toolkit\",\"authors\":\"D. Satybaldina, N.K. Bisenbaeva, Y. Seitkulov, A.K. Seksenbaeva\",\"doi\":\"10.32523/2616-7182/bulmathenu.2023/1.2\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"In modern conditions of digital technologies implementation in various sectors of the economy, the digitalization of public administration, healthcare, education, and science, the growth in the number of Internet services and mobile devices the issues of ensuring the security of cellular communication systems are becoming increasingly relevant. It is becoming increasingly difficult to detect multiple and complex cyber security threats as the sources and methods ofcyber-attacks evolve and expand. Classic network attack detection approaches that rely heavily on static matching, such as signature analysis, blacklisting, or regular expression patterns, are limited in flexibility and are ineffective for early anomaly detection and rapid response to information security incidents. To solve this problem, the use of machine learning (ML) algorithms is proposed. ML methods can provide new approaches and higher rates of detection of malicious activity on the network. In this work, the Splunk Enterprise data analysis platform and the Splunk Machine Learning Toolkit for creating, training, testing, and validating a network attack classifier are used. The performance of the proposed model was evaluatedby applying four machine learning algorithms such as a decision tree, a support vector machine, a random forest, and adouble random forest. Experimental results show that all used ML algorithms can be effectively used to detect network attacks, and the double random forest method has the best accuracy in detecting distributed denial-of-service attacks.\",\"PeriodicalId\":286555,\"journal\":{\"name\":\"BULLETIN of the L N Gumilyov Eurasian National University MATHEMATICS COMPUTER SCIENCE MECHANICS Series\",\"volume\":\"113 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-03-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"BULLETIN of the L N Gumilyov Eurasian National University MATHEMATICS COMPUTER SCIENCE MECHANICS Series\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.32523/2616-7182/bulmathenu.2023/1.2\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"BULLETIN of the L N Gumilyov Eurasian National University MATHEMATICS COMPUTER SCIENCE MECHANICS Series","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.32523/2616-7182/bulmathenu.2023/1.2","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

在经济各个部门实施数字技术的现代条件下,公共管理、医疗保健、教育和科学的数字化,互联网服务和移动设备数量的增长,确保蜂窝通信系统安全的问题变得越来越重要。随着网络攻击来源和方法的不断发展和扩展,检测多种复杂的网络安全威胁变得越来越困难。传统的网络攻击检测方法严重依赖静态匹配,如特征分析、黑名单、正则表达式模式等,其灵活性有限,无法实现早期异常检测和快速响应信息安全事件。为了解决这个问题,提出了使用机器学习(ML)算法。机器学习方法可以提供新的方法和更高的网络恶意活动检测率。在这项工作中,使用Splunk Enterprise数据分析平台和Splunk机器学习工具包来创建、训练、测试和验证网络攻击分类器。采用决策树、支持向量机、随机森林和双随机森林四种机器学习算法对模型的性能进行了评价。实验结果表明,采用的所有ML算法都能有效地检测网络攻击,其中双随机森林方法在检测分布式拒绝服务攻击方面准确率最高。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Detecting and classifying network attacks with Splunk Machine Learning Toolkit
In modern conditions of digital technologies implementation in various sectors of the economy, the digitalization of public administration, healthcare, education, and science, the growth in the number of Internet services and mobile devices the issues of ensuring the security of cellular communication systems are becoming increasingly relevant. It is becoming increasingly difficult to detect multiple and complex cyber security threats as the sources and methods ofcyber-attacks evolve and expand. Classic network attack detection approaches that rely heavily on static matching, such as signature analysis, blacklisting, or regular expression patterns, are limited in flexibility and are ineffective for early anomaly detection and rapid response to information security incidents. To solve this problem, the use of machine learning (ML) algorithms is proposed. ML methods can provide new approaches and higher rates of detection of malicious activity on the network. In this work, the Splunk Enterprise data analysis platform and the Splunk Machine Learning Toolkit for creating, training, testing, and validating a network attack classifier are used. The performance of the proposed model was evaluatedby applying four machine learning algorithms such as a decision tree, a support vector machine, a random forest, and adouble random forest. Experimental results show that all used ML algorithms can be effectively used to detect network attacks, and the double random forest method has the best accuracy in detecting distributed denial-of-service attacks.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信