Clustering phase: uses an unsupervised algorithm, K clusters are created from an unlabelled dataset that collects the normal network behaviour.
Outlier detection phase: all the outliers, from the K clusters, are (1) removed from the dataset because they are considered noise and will be compromising the performance of algorithms, (2) or defined as anormal. The resulting dataset is combined with another known dataset (for example IoT233 dataset or others to enhance the classification with known threats/anomalies).
Classification phase: the classification algorithm is trained using the combined dataset from the previous phase. The output of this phase is the ADI model, a trained machine-learning model which will be used in the last phase.
Predict phase: in this phase, the new incoming traffic will be analysed and classified as normal or anormal using the ADI model.
| Short name | Short description | Priority |
| attempted-user | Attempted User Privilege Gain | 1 |
| unsuccessful-user | Unsuccessful User Privilege Gain | 1 |
| successful-user | Successful User Privilege Gain | 1 |
| attempted-admin | Attempted Administrator Privilege Gain | 1 |
| successful-admin | Successful Administrator Privilege Gain | 1 |
| shellcode-detect | Executable Code was Detected | 1 |
| trojan-activity | A Network Trojan was Detected | 1 |
| web-application-attack | Web Application Attack | 1 |
| inappropriate-content | Inappropriate Content was Detected | 1 |
| policy-violation | Potential Corporate Privacy Violation | 1 |
| file-format | Known malicious file or file-based exploit | 1 |
| malware-cnc | Known malware command and control traffic | 1 |
| client-side-exploit | Known client-side exploit attempt | 1 |
| bad-unknown | Potentially Bad Traffic | 2 |
| attempted-recon | Attempted Information Leak | 2 |
| successful-recon-limited | Information Leak | 2 |
| successful-recon-largescale | Large Scale Information Leak | 2 |
| attempted-dos | Attempted Denial of Service | 2 |
| successful-dos | Denial of Service | 2 |
| rpc-portmap-decode | Decode of an RPC Query | 2 |
| suspicious-filename-detect | A Suspicious Filename was Detected | 2 |
| suspicious-login | An Attempted Login Using a Suspicious Username was Detected | 2 |
| system-call-detect | A System Call was Detected | 2 |
| unusual-client-port-connection | A Client was Using an Unusual Port | 2 |
| denial-of-service | Detection of a Denial of Service Attack | 2 |
| non-standard-protocol | Detection of a Non-Standard Protocol or Event | 2 |
| web-application-activity | Access to a Potentially Vulnerable Web Application | 2 |
| misc-attack | Misc Attack | 2 |
| default-login-attempt | Attempt to Login By a Default Username and Password | 2 |
| sdf | Sensitive Data was Transmitted Across the Network | 2 |
| not-suspicious | Not Suspicious Traffic | 3 |
| unknown | Unknown Traffic | 3 |
| string-detect | A Suspicious String was Detected | 3 |
| network-scan | Detection of a Network Scan | 3 |
| protocol-command-decode | Generic Protocol Command Decode | 3 |
| misc-activity | Misc activity | 3 |
| icmp-event | Generic ICMP event | 3 |
| tcp-connection | A TCP Connection was Detected | 4 |
| attempted-user | Attempted User Privilege Gain | 1 |
| unsuccessful-user | Unsuccessful User Privilege Gain | 1 |
| successful-user | Successful User Privilege Gain | 1 |
| attempted-admin | Attempted Administrator Privilege Gain | 1 |
| successful-admin | Successful Administrator Privilege Gain | 1 |
| shellcode-detect | Executable Code was Detected | 1 |
| trojan-activity | A Network Trojan was Detected | 1 |
| web-application-attack | Web Application Attack | 1 |
| inappropriate-content | Inappropriate Content was Detected | 1 |
| policy-violation | Potential Corporate Privacy Violation | 1 |
| file-format | Known malicious file or file-based exploit | 1 |
| malware-cnc | Known malware command and control traffic | 1 |
| client-side-exploit | Known client-side exploit attempt | 1 |
| bad-unknown | Potentially Bad Traffic | 2 |
| attempted-recon | Attempted Information Leak | 2 |
| successful-recon-limited | Information Leak | 2 |
| successful-recon-largescale | Large Scale Information Leak | 2 |
| attempted-dos | Attempted Denial of Service | 2 |
| successful-dos | Denial of Service | 2 |
| rpc-portmap-decode | Decode of an RPC Query | 2 |
| suspicious-filename-detect | A Suspicious Filename was Detected | 2 |
| suspicious-login | An Attempted Login Using a Suspicious Username was Detected | 2 |
| system-call-detect | A System Call was Detected | 2 |
| unusual-client-port-connection | A Client was Using an Unusual Port | 2 |
| denial-of-service | Detection of a Denial of Service Attack | 2 |
| non-standard-protocol | Detection of a Non-Standard Protocol or Event | 2 |
| web-application-activity | Access to a Potentially Vulnerable Web Application | 2 |
| misc-attack | Misc Attack | 2 |
| default-login-attempt | Attempt to Login By a Default Username and Password | 2 |
| sdf | Sensitive Data was Transmitted Across the Network | 2 |
| not-suspicious | Not Suspicious Traffic | 3 |
| unknown | Unknown Traffic | 3 |
| string-detect | A Suspicious String was Detected | 3 |
| network-scan | Detection of a Network Scan | 3 |
| protocol-command-decode | Generic Protocol Command Decode | 3 |
| misc-activity | Misc activity | 3 |
| icmp-event | Generic ICMP event | 3 |
| tcp-connection | A TCP Connection was Detected | 4 |
| Script | Training |
| Purpose | Train the anomaly detection model with Density-Based Spatial Clustering of Applications with Noise (DBSCAN ) for clustering and outlier detection and Random Forest for classification using the input dataset, or the NF-TON-IoT[1] dataset |
| Functionalities |
|
| Notes | The default dataset NF-TON-IoT could be replaced with other more recent known dataset |
| Train the anomaly
detection model with Density-Based Spatial
Clustering of Applications with Noise
( | |
Load and preprocess the input dataset, or the NFTON-IoT dataset Train and generate the model Save the trained model to disk for later use | |
| The default dataset NF-TON-IoT could be replaced with other more recent known dataset |
| Script | Prediction/monitoring | |||||
| Purpose | Monitor network packets from a file, in semi real-time, classify packets as anomalous or normal, and log the results. | |||||
| Functionalities | Continuously read a network traffic packets from a fileExtract and preprocess features from each packetApply trained model generated by the training script to classify packets Log anomalies for further analysis | |||||
| Monitor network packets from a file, in semi real-time, classify packets as anomalous or normal, and log the results. | ||||||
| Continuously read a network traffic packets from a fileExtract and preprocess features from each packetApply trained model generated by the training script to classify packets Log anomalies for further analysis | ||||||
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.