Skip to search boxSkip to navigationSkip to main content

Differentiating and Predicting Cyberattack Behaviors Using LSTM

  • Rochester Institute of Technology
Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution

Abstract

Classifying and predicting cyberattack behaviors are outstanding challenges due to the changing and broad attack surfaces as attackers penetrate into enterprise networks. The rise of Recurrent Neural Networks (RNNs) for temporally structured data in machine learning presents an opportunity to address these challenges, though it would require sufficient data and reasonable labels indicative of attack behaviors. This paper presents the use of RNNs to model penetration behaviors exhibited by ten teams in the 2017 Collegiate Penetration Testing Competition (CPTC'17). The Long-Short-Term-Memory (LSTM) models obtained by training on the CPTC data enable the assessment of the differentiability of attack behaviors across teams and the predictability of future actions. This first-of-its kind attempt presents observations and insights for how earlier attack actions may or may not be indicative of future behaviors. The paper concludes with future considerations to integrate the LSTM models and enable predictive analytics to defend against complex, multistage cyberattacks.

Bibliographic Information

Output type

Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution

Original language

English

Article number

8625145

Publication milestones

  • Published - 23/01/2019

Publication status

Published - 23/01/2019

Publisher

Institute of Electrical and Electronics Engineers Inc.

Publication series

  • Publication series name: DSC 2018 - 2018 IEEE Conference on Dependable and Secure Computing

ISBN (Electronic)

9781538657904

Publication IDs

  • Scopus: 85062512210

Host publication title

DSC 2018 - 2018 IEEE Conference on Dependable and Secure Computing