PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
August 25, 2016The Journal of Defense Modeling and Simulation Applications Methodology Technology15 citations

Feature extraction and feature selection for classifying cyber traffic threats

View Full Paper
KMKristy L MooreTBTrevor BihlKBKenneth W. Bauer

Key Points

Key points are not available for this paper at this time.

Abstract

Cyber networks frequently encounter amounts of network traffic too large to process real-time threat detection efficiently. This research examines combined classification and feature selection using the artificial neural network (ANN) for cyber network threat detection. Examined network traffic data was from the 2003–2007 and 2009 Department of Defense Cyber Defense Exercises (CDXs). Firstly, a feature extraction process is developed using Fullstats to extract 248 features from the CDX dataset. Security Onion is used to determine class labels (cyber attack and severity of attack). Various threat detection scenarios are considered in analyzing the data: threats versus no-threats, severity of threats (low, medium, and high) for known threats, and complete (no-threat, low, medium, and high). ANN signal-to-noise ratio feature selection was used to remove non-salient features and determine an appropriate level of dimensionality for classifying cyber attack and normal operating conditions. Considering the set of 248 features from the CDX data, consistent classification accuracy of 83–97% (testing/training sets) and 63–88% (validation sets) is seen until 18 features. Thus, a 90% data reduction is shown to be possible with negligible reduction in performance with additional insight into the source (Transmission Control Protocol/Internet Protocol or Open Systems Interconnection layer) of salient features.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Moore et al. (2016) studied this question.

synapsesocial.com/papers/6a206f0c82e2e39577029b81https://doi.org/10.1177/1548512916664032
Ask AI
Helpful
Bookmark
Share
View Full Paper