Back to results

Department of Computer Science

Using machine learning to guide automated intrusion response

Abstract

dc:description.abstract

Traditionally Intrusion Response Systems (IRSs) have had a strong reliance on net-work administrators to perform various responses for a network. Though this is expected, particularly with networks containing sensitive data, it is not completely practical, considering the ever-growing demand for speed, scalability, and automation in computer networks. This work presents a proof of concept automated IRS that provides both for networks containing sensitive data and high-speed networks, by using basic responses for complex attacks, and by using reinforcement learning for direct attacks. Responses for the latter are done by creating a response system that is able to learn from the effectiveness of its own responses. This work is evaluated in its effectiveness against the deactivation issue, which is concerned with the problem of automatically deactivating network responses after they've been activated by an IRS. All tests are conducted using an emulated network, that was de-signed to replicate real network behaviour. Simulated attacks were used to train the IRS. Results of training were evaluated at intervals of 100, 500, 1000 and 2000 at-tacks. The findings of this work indicate that while applying reinforcement learning to IRSs is feasible, adjustments may still be required to improve its performance.

Degree

thesis:*
Grantor
Department of Computer Science
Year dc:date.issued
2020

Author and committee

dc:creator, dc:contributor.*
Author dc:creator
  • Lopes, Andre
Advisor dc:contributor.advisor
  • Hutchison, Andrew

Subjects

dc:subject × 1

Identifiers

dc:identifier.*
Handle dc:identifier.uri
http://hdl.handle.net/11427/32403
OAI identifier oai:identifier
oai:open.uct.ac.za:11427/32403

Chain of custody

source
Harvested from
University of Cape Town
Base URL
open.uct.ac.za/oai/request
Last updated
2026-07-22
Source record
OAI-PMH GetRecord
citation

Lopes, Andre. Using machine learning to guide automated intrusion response. Department of Computer Science, 2020. http://hdl.handle.net/11427/32403