• Journal of Internet Computing and Services
    ISSN 2287 - 1136 (Online) / ISSN 1598 - 0170 (Print)
    https://jics.or.kr/

Detection of Signs of Hostile Cyber Activity against External Networks based on Autoencoder


Hansol Park, Kookjin Kim, Jaeyeong Jeong, jisu Jang, Jaepil Youn, Dongkyoo Shin, Journal of Internet Computing and Services, Vol. 23, No. 6, pp. 39-48, Dec. 2022
10.7472/jksii.2022.23.6.39, Full Text:
Keywords: Anomaly Detection, Autoencoder, BGP Archive Data

Abstract

Cyberattacks around the world continue to increase, and their damage extends beyond government facilities and affects civilians. These issues emphasized the importance of developing a system that can identify and detect cyber anomalies early. As above, in order to effectively identify cyber anomalies, several studies have been conducted to learn BGP (Border Gateway Protocol) data through a machine learning model and identify them as anomalies. However, BGP data is unbalanced data in which abnormal data is less than normal data. This causes the model to have a learning biased result, reducing the reliability of the result. In addition, there is a limit in that security personnel cannot recognize the cyber situation as a typical result of machine learning in an actual cyber situation. Therefore, in this paper, we investigate BGP (Border Gateway Protocol) that keeps network records around the world and solve the problem of unbalanced data by using SMOTE. After that, assuming a cyber range situation, an autoencoder classifies cyber anomalies and visualizes the classified data. By learning the pattern of normal data, the performance of classifying abnormal data with 92.4% accuracy was derived, and the auxiliary index also showed 90% performance, ensuring reliability of the results. In addition, it is expected to be able to effectively defend against cyber attacks because it is possible to effectively recognize the situation by visualizing the congested cyber space.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from November 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[APA Style]
Park, H., Kim, K., Jeong, J., Jang, j., Youn, J., & Shin, D. (2022). Detection of Signs of Hostile Cyber Activity against External Networks based on Autoencoder. Journal of Internet Computing and Services, 23(6), 39-48. DOI: 10.7472/jksii.2022.23.6.39.

[IEEE Style]
H. Park, K. Kim, J. Jeong, j. Jang, J. Youn, D. Shin, "Detection of Signs of Hostile Cyber Activity against External Networks based on Autoencoder," Journal of Internet Computing and Services, vol. 23, no. 6, pp. 39-48, 2022. DOI: 10.7472/jksii.2022.23.6.39.

[ACM Style]
Hansol Park, Kookjin Kim, Jaeyeong Jeong, jisu Jang, Jaepil Youn, and Dongkyoo Shin. 2022. Detection of Signs of Hostile Cyber Activity against External Networks based on Autoencoder. Journal of Internet Computing and Services, 23, 6, (2022), 39-48. DOI: 10.7472/jksii.2022.23.6.39.