BlackEye: automatic IP blacklisting using machine learning from security logs

Citations

WEB OF SCIENCE

11
Citations

SCOPUS

15

초록

Blacklisting of malicious IP address is a primary technique commonly used for safeguarding mission-critical IT systems. The decision to blacklist an IP address requires careful examination of various aspects of packet traffic data as well as the behavioral history. Most of the current security monitoring for IP blacklisting heavily relies on the domain expertise from experienced specialists. Although there are efforts to apply machine-learning (ML) techniques to this problem, we are yet to see the mature solution. To mitigate these challenges and to gain better understanding of the problem, we have designed the BlackEye framework in which we can apply various ML techniques and produce models for accurate blacklisting. From our analysis results, we learn that multi-staged method that combines the data cleansing and the classification via logistic regression or random forest produces the best results. Our evaluation on the real-world data shows that it can reduce the the incorrect blacklisting by nearly 90% when compared to the performance of experts. More over, our proposed model performed well in terms of the time-to-blacklist by curtailing the period of malicious IP address in activity by 27 days on average.

키워드

Blacklisting; Security logs; Machine learning; Linear regression
제목
BlackEye: automatic IP blacklisting using machine learning from security logs
저자
Jeon, Dooyong; Tak, Byungchul
DOI
10.1007/s11276-019-02201-5
발행일
2022-02
유형
Article
저널명
Wireless Networks
권
28
호
2
페이지
937 ~ 948