CAMLPAD: Cybersecurity Autonomous Machine Learning Platform for Anomaly Detection

被引:9
|
作者
Hariharan, Ayush [1 ]
Gupta, Ankit [1 ]
Pal, Trisha [1 ]
机构
[1] Blue Cloak LLC, Sterling, VA 20164 USA
来源
ADVANCES IN INFORMATION AND COMMUNICATION, VOL 2 | 2020年 / 1130卷
关键词
Machine learning; Cybersecurity; Anomaly detection; Clustering; Visualization; INTRUSION DETECTION; DETECTION FRAMEWORK; SYSTEM;
D O I
10.1007/978-3-030-39442-4_52
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As machine learning and cybersecurity continue to explode in the context of the digital ecosystem, the complexity of cybersecurity data combined with complicated and evasive machine learning algorithms leads to vast difficulties in designing an end-to-end system for intelligent, automatic anomaly classification. On the other hand, traditional systems use elementary statistics techniques and are often inaccurate, leading to weak centralized data analysis platforms. In this paper, we propose a novel system that addresses these two problems, titled CAMLPAD, for Cybersecurity Autonomous Machine Learning Platform for Anomaly Detection. The CAMLPAD system's streamlined, holistic approach begins with retrieving a multitude of different species of cybersecurity data in real-time using elasticsearch, then running several machine learning algorithms, namely Isolation Forest, Histogram-Based Outlier Score (HBOS), Cluster-Based Local Outlier Factor (CBLOF), and K-Means Clustering, to process the data. Next, the calculated anomalies are visualized using Kibana and are assigned an outlier score, which serves as an indicator for whether an alert should be sent to the system administrator that there are potential anomalies in the network. After comprehensive testing of our platform in a simulated environment, the CAMLPAD system achieved an adjusted rand score of 95%, exhibiting the reliable accuracy and precision of the system. All in all, the CAMLPAD system provides an accurate, streamlined approach to real-time cybersecurity anomaly detection, delivering a novel solution that has the potential to revolutionize the cybersecurity sector.
引用
收藏
页码:705 / 720
页数:16
相关论文
共 50 条
  • [1] Design and Evaluation of Unsupervised Machine Learning Models for Anomaly Detection in Streaming Cybersecurity Logs
    Sanchez-Zas, Carmen
    Larriva-Novo, Xavier
    Villagra, Victor A.
    Rodrigo, Mario Sanz
    Moreno, Jose Ignacio
    MATHEMATICS, 2022, 10 (21)
  • [2] Machine learning in cybersecurity: a comprehensive survey
    Dasgupta, Dipankar
    Akhtar, Zahid
    Sen, Sajib
    JOURNAL OF DEFENSE MODELING AND SIMULATION-APPLICATIONS METHODOLOGY TECHNOLOGY-JDMS, 2022, 19 (01): : 57 - 106
  • [3] Machine Learning for Anomaly Detection: A Systematic Review
    Nassif, Ali Bou
    Talib, Manar Abu
    Nasir, Qassim
    Dakalbab, Fatima Mohamad
    IEEE ACCESS, 2021, 9 : 78658 - 78700
  • [4] Cybersecurity Attack Detection Model, Using Machine Learning Techniques
    Avci, Isa
    Koca, Murat
    ACTA POLYTECHNICA HUNGARICA, 2023, 20 (07) : 29 - 44
  • [5] Review: machine learning techniques applied to cybersecurity
    Martinez Torres, Javier
    Iglesias Comesana, Carla
    Garcia-Nieto, Paulino J.
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2019, 10 (10) : 2823 - 2836
  • [6] Efficient Distributed Preprocessing Model for Machine Learning-Based Anomaly Detection over Large-Scale Cybersecurity Datasets
    Larriva-Novo, Xavier
    Vega-Barbas, Mario
    Villagra, Victor A.
    Rivera, Diego
    Alvarez-Campana, Manuel
    Berrocal, Julio
    APPLIED SCIENCES-BASEL, 2020, 10 (10):
  • [7] Quantum machine learning algorithms for anomaly detection: A review
    Corli, Sebastiano
    Moro, Lorenzo
    Dragoni, Daniele
    Dispenza, Massimiliano
    Prati, Enrico
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2025, 166
  • [8] Anomaly Detection for Cybersecurity of the Substations
    Ten, Chee-Wooi
    Hong, Junho
    Liu, Chen-Ching
    IEEE TRANSACTIONS ON SMART GRID, 2011, 2 (04) : 865 - 873
  • [9] Cybersecurity in the AI era: analyzing the impact of machine learning on intrusion detection
    Dong, Huiyao
    Kotenko, Igor
    KNOWLEDGE AND INFORMATION SYSTEMS, 2025, : 3915 - 3966
  • [10] Machine Learning and Deep Learning Methods for Cybersecurity
    Xin, Yang
    Kong, Lingshuang
    Liu, Zhi
    Chen, Yuling
    Li, Yanmiao
    Zhu, Hongliang
    Gao, Mingcheng
    Hou, Haixia
    Wang, Chunhua
    IEEE ACCESS, 2018, 6 : 35365 - 35381