Accession Number:

AD1056317

Title:

Cyber Data Anomaly Detection Using Autoencoder Neural Networks

Descriptive Note:

Technical Report,01 Aug 2016,22 Mar 2018

Corporate Author:

AIR FORCE INSTITUTE OF TECHNOLOGY WRIGHT-PATTERSON AFB OH WRIGHT-PATTERSON AFB United States

Personal Author(s):

Report Date:

2018-03-22

Pagination or Media Count:

151.0

Abstract:

The Department of Defense requires a secure presence in the cyber domain to successfully execute its stated mission of deterring war and protecting the security of the United States. With potentially millions of logged network events occurring on defended networks daily, a limited staff of cyber analysts require the capability to identify novel network actions for security adjudication. The detection methodology proposed uses an autoencoder neural network optimized via design of experiments for the identification of anomalous network events. Once trained, each logged network event is analyzed by the neural network and assigned an outlier score. The network events with the largest outlier scores are anomalous and worthy of further review by cyber analysts. This neural network approach can operate in conjunction with alternate tools for outlier detection, enhancing the overall anomaly detection capability of cyber analysts.

Subject Categories:

  • Cybernetics
  • Computer Systems Management and Standards

Distribution Statement:

APPROVED FOR PUBLIC RELEASE