Anomaly Based Hybrid Cyber Threat Detection System
There are teo types of detection systems SIGNATURE BASED and ANOMALY BASED but to detect a zero day or unknown attack signature detection system failes then comes anomaly based detection systems Our project is an anomaly based cyber threat detection system using deep learning.To improve the d
2025-06-28 16:25:07 - Adil Khan
Anomaly Based Hybrid Cyber Threat Detection System
Project Area of Specialization Cyber SecurityProject SummaryThere are teo types of detection systems SIGNATURE BASED and ANOMALY BASED but to detect a zero day or unknown attack signature detection system failes then comes anomaly based detection systems
Our project is an anomaly based cyber threat detection system using deep learning.To improve the detection we generate different patterns of threats from known threat so if any known threat comes in a disguised form our system is abe to detect it.
Project Objectives- To develop an asset register map with the risk to be associated with the particular asset
- To develop a unique and highly accurate intrusion detection and prevention system.
- To develop a mechanism to identify the potential threat associated with the multiple assets of the same organization simultaneously.
Our detection system is composed of two levels of classification. On first level there is a
multi-classifier and on second level there are three binary classifiers for each attack kind.
(DOS, PROBE, R2L) The network traffic first goes to the first level multi-classifier which
detects if there is a threat in network traffic and detects the threat kind. If any threat kind is
detected, the network traffic goes to respective classifier for verification to attain highly
efficient model. But if network traffic is normal or not anomalous then second level
verification does not take place .For example DOS attack is detected by the multi-classifier
at the first level then DOS attack is verified by the DOS binary classifier at the second level.
To develop a highly efficient classification model, we preprocess data (NSL-KDD Dataset)
using three steps of feature engineering.
1. Categorical Data Encoding.
2. Feature Selection.
3. Dimensionality Reduction.
After preprocessing we filter dataset according to attack kind. To accomplish target of
detecting zero day attack we generate the synthetic instances of each kind using GANs so
that attack is detected even if it is in disguised form. All the classifiers are trained on dataset,
preprocessed on each combination. Then finally the combination that gives the best results
is selected for each classifier.
Although many detection systems are available but generating different patterns of threats using GANs is not implemented yet and it surely increases the detection rate and highly efficient detection systems is need of the time.
Technical Details of Final DeliverableOur final system having embeddes highly efficient classifiers which is classifying the live netwrok traffic among three kinds of attcks (DOS,Probe,R2L) and all these detection are shown in a dashboard.
Final Deliverable of the Project Software SystemCore Industry SecurityOther Industries Legal , Media , Health , Telecommunication Core Technology Artificial Intelligence(AI)Other Technologies OthersSustainable Development Goals Industry, Innovation and Infrastructure, Reduced InequalityRequired Resources| Item Name | Type | No. of Units | Per Unit Cost (in Rs) | Total (in Rs) |
|---|---|---|---|---|
| Total in (Rs) | 76100 | |||
| Router | Equipment | 1 | 20000 | 20000 |
| Switch | Equipment | 0 | 1950 | 0 |
| Ethernet Cables | Equipment | 10 | 1150 | 11500 |
| Hard disk | Equipment | 4 | 7000 | 28000 |
| Modem | Equipment | 2 | 3300 | 6600 |
| Overhead | Miscellaneous | 1 | 10000 | 10000 |