2019/07/23 by Ayush Hariharan, Ankit Gupta, Hariharan, Ayush +3 · 1 citation
Computer Science · #Advanced Malware Detection Techniques #Anomaly Detection Techniques and Applications #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Machine Learning (cs.LG) #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI)
paper · pdf · doi:10.48550/arxiv.1907.10442
openalex publication_date 2019/07/23 · openalex created_date 2022/07/28 · openalex updated_date 2026/07/28
As machine learning and cybersecurity continue to explode in the context of\nthe digital ecosystem, the complexity of cybersecurity data combined with\ncomplicated and evasive machine learning algorithms leads to vast difficulties\nin designing an end to end system for intelligent, automatic anomaly\nclassification. On the other hand, traditional systems use elementary\nstatistics techniques and are often inaccurate, leading to weak centralized\ndata analysis platforms. In this paper, we propose a novel system that\naddresses these two problems, titled CAMLPAD, for Cybersecurity Autonomous\nMachine Learning Platform for Anomaly Detection. The CAMLPAD systems\nstreamlined, holistic approach begins with retrieving a multitude of different\nspecies of cybersecurity data in real time using elasticsearch, then running\nseveral machine learning algorithms, namely Isolation Forest, Histogram Based\nOutlier Score (HBOS), Cluster Based Local Outlier Factor (CBLOF), and K Means\nClustering, to process the data. Next, the calculated anomalies are visualized\nusing Kibana and are assigned an outlier score, which serves as an indicator\nfor whether an alert should be sent to the system administrator that there are\npotential anomalies in the network. After comprehensive testing of our platform\nin a simulated environment, the CAMLPAD system achieved an adjusted rand score\nof 95 percent, exhibiting the reliable accuracy and precision of the system.\nAll in all, the CAMLPAD system provides an accurate, streamlined approach to\nreal time cybersecurity anomaly detection, delivering a novel solution that has\nthe potential to revolutionize the cybersecurity sector.\n