English

End-To-End Anomaly Detection for Identifying Malicious Cyber Behavior through NLP-Based Log Embeddings

Artificial Intelligence 2021-08-30 v1 Cryptography and Security

Abstract

Rule-based IDS (intrusion detection systems) are being replaced by more robust neural IDS, which demonstrate great potential in the field of Cybersecurity. However, these ML approaches continue to rely on ad-hoc feature engineering techniques, which lack the capacity to vectorize inputs in ways that are fully relevant to the discovery of anomalous cyber activity. We propose a deep end-to-end framework with NLP-inspired components for identifying potentially malicious behaviors on enterprise computer networks. We also demonstrate the efficacy of this technique on the recently released DARPA OpTC data set.

Keywords

Cite

@article{arxiv.2108.12276,
  title  = {End-To-End Anomaly Detection for Identifying Malicious Cyber Behavior through NLP-Based Log Embeddings},
  author = {Andrew Golczynski and John A. Emanuello},
  journal= {arXiv preprint arXiv:2108.12276},
  year   = {2021}
}

Comments

Presented at 1st International Workshop on Adaptive Cyber Defense, 2021 (arXiv:2108.08476)

R2 v1 2026-06-24T05:28:13.980Z