The detection of cyber threats has recently been a crucial research domain as the internet and data drive people's livelihood. Several cyberattacks lead to the compromise of data security. The proposed system offers complete data protection from Advanced Persistent Threat (APT) attacks with attack detection and defence mechanisms. The modified lateral movement detection algorithm detects the APT attacks, while the defence is achieved by the Dynamic Deception system that makes use of the belief update algorithm. Before termination, every cyber-attack undergoes multiple stages, with the most prominent stage being Lateral Movement (LM). The LM uses a Remote Desktop protocol (RDP) technique to authenticate the unauthorised host leaving footprints on the network and host logs. An anomaly-based approach leveraging the RDP event logs on Windows is used for detecting the evidence of LM. After extracting various feature sets from the logs, the RDP sessions are classified using machine-learning techniques with high recall and precision. It is found that the AdaBoost classifier offers better accuracy, precision, F1 score and recall recording 99.9%, 99.9%, 0.99 and 0.98%. Further, a dynamic deception process is used as a defence mechanism to mitigate APT attacks. A hybrid encryption communication, dynamic (Internet Protocol) IP address generation, timing selection and policy allocation are established based on mathematical models. A belief update algorithm controls the defender's action. The performance of the proposed system is compared with the state-of-the-art models.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
hi@scite.ai
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
Copyright © 2024 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.