H2O.ai
Machine Intelligence
Exploiting Sequence of Events for Potential Attack Detection in - - PowerPoint PPT Presentation
Exploiting Sequence of Events for Potential Attack Detection in Network Security using Machine Learning Ashrith Barthur, PhD Security Research @cyberbaggage H 2 O .ai Machine Intelligence Sequence of Events (SoE) What is a Sequence of
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
goal.
H2O.ai
Machine Intelligence
achieve a state.
H2O.ai
Machine Intelligence
that important.
sequence of events is important.
H2O.ai
Machine Intelligence
sequence, by actual data joins, or algorithmically.
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
unused access, network segments without VLANs, un-closed, outdated wall sockets, etc.
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
before an attack is launched.
H2O.ai
Machine Intelligence
all around the world might be working on the same database.
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
Rule-based Model Feature-based Model Pure Data Driven Model
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
attacks by: ○ First marking the kind of traffic it is. ○ And the likelihood of it being malicious
the outcome of the model.
H2O.ai
Machine Intelligence
and the algorithm.
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
average tcp connect length by protocol 7 Days
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
Logs Information Analytical Inputs:
Suspicious Not Suspicious
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O Unsupervised Algorithm
SoC Analyst
Clustering Output Sampling
Clustering output labeling
Clustering Classification Output Logs/Pcap
H2O.ai
Machine Intelligence
Data with Features Not Suspicious
H2O Machine Learning Algorithm
Suspicious
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
H2O.ai
Machine Intelligence
candidates
multi-classification.
scores.
different scores when compared to benign events.
H2O.ai
Machine Intelligence
reconstruction errors.
anomalous - potential attack, and benign.
H2O.ai
Machine Intelligence
attacks.
H2O.ai
Machine Intelligence