• Login
    View Item 
    •   Research Bank Home
    • Unitec Institute of Technology
    • Study Areas
    • Computing
    • Computing Dissertations and Theses
    • View Item
    •   Research Bank Home
    • Unitec Institute of Technology
    • Study Areas
    • Computing
    • Computing Dissertations and Theses
    • View Item
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    A hybrid intelligent intrusion detection system for advanced persistent threats

    Miguez, Manuel

    Thumbnail
    Share
    View fulltext online
    MComp_2020_Manuel Miguez +.pdf (14.18Mb)
    Date
    2020
    Citation:
    Miguez, M. (2020). A hybrid intelligent intrusion detection system for advanced persistent threats. (Unpublished document submitted in partial fulfilment of the requirements for the degree of Master of Computing). Unitec Institute of Technology, Auckland, New Zealand. Retrieved from https://hdl.handle.net/10652/5071
    Permanent link to Research Bank record:
    https://hdl.handle.net/10652/5071
    Abstract
    RESEARCH MOTIVATION: The objective of this research is to investigate how to increase the detection rate and increase the tracking rate of APT and TA in their early attack phases within an environment of distributed networks. ABSTRACT: Today's world has networks without clear frontiers, where employees can and do work outside the company protection systems. Furthermore, they use two or more devices providing many possible entry points for attackers. Large scale attacks are often unknowingly initiated by these users. Large scale Targeted Attacks (TA) are slow, fragmented, distributed, seemingly unrelated, and very sophisticated attacks targeting high-value organisations, and these attacks are often executed over long periods. When nations or states back these attacks, they are known as Advanced Persistent Threat (APT). This research focuses on developing a methodology capable of detecting an APT in its early stages combining an Artificial Immune System (AIS) methodology known as Dendritic Cell Algorithm (DCA) with Genetic Algorithm (GA) and Support Vector Machine (SVM) classifiers. This Hybrid Model uses GA for feature extraction and SVM for DCA Signal Selection during the pre-processing stage, and DCA is the classifier for the Traffic Processing and Decision Modules during the processing phase. The Signal Selection process applies a cumulative distribution function of the Pareto distribution model to the results obtained with SVM to produce the DCA Safe and Danger signals. The Traffic Processing stage presents two linear equations and their weights for implementation on different types of datasets. Finally, the Decision Module calculates the Anomaly Threshold required for the dataset classification by obtaining the intersection of the distribution of the training normal and abnormal scores.
    Keywords:
    advanced persistent threat (APT), intrusion prevention system (IPS), intrusion detection system (IDS), artificial intelligence (AI), AI, cybersecurity
    ANZSRC Field of Research:
    080303 Computer System Security
    Degree:
    Master of Computing, Unitec Institute of Technology
    Supervisors:
    Sarrafpour, Bahman
    Copyright Holder:
    Author

    Copyright Notice:
    All rights reserved
    Rights:
    This digital work is protected by copyright. It may be consulted by you, provided you comply with the provisions of the Act and the following conditions of use. These documents or images may be used for research or private study purposes. Whether they can be used for any other purpose depends upon the Copyright Notice above. You will recognise the author's and publishers rights and give due acknowledgement where appropriate.
    Metadata
    Show detailed record
    This item appears in
    • Computing Dissertations and Theses [90]

    Te Pūkenga

    Research Bank is part of Te Pūkenga - New Zealand Institute of Skills and Technology

    • About Te Pūkenga
    • Privacy Notice

    Copyright ©2022 Te Pūkenga

    Usage

    Downloads, last 12 months
    2,162
     
     

    Usage Statistics

    For this itemFor the Research Bank

    Share

    About

    About Research BankContact us

    Help for authors  

    How to add research

    Register for updates  

    LoginRegister

    Browse Research Bank  

    EverywhereInstitutionsStudy AreaAuthorDateSubjectTitleType of researchSupervisorCollaboratorThis CollectionStudy AreaAuthorDateSubjectTitleType of researchSupervisorCollaborator

    Te Pūkenga

    Research Bank is part of Te Pūkenga - New Zealand Institute of Skills and Technology

    • About Te Pūkenga
    • Privacy Notice

    Copyright ©2022 Te Pūkenga