| | SLO | ENG | Cookies and privacy

Bigger font | Smaller font

Show document Help

Title:Uporaba metod strojnega učenja za zaznavanje kompleksnejših kibernetskih groženj
Authors:ID Rotovnik, Maja (Author)
ID Hölbl, Marko (Mentor) More about this mentor... New window
Files:.pdf MAG_Rotovnik_Maja_2025.pdf (1,99 MB)
MD5: 93AD3AE1BEA708BA61A7CB648348CDEB
 
Language:Slovenian
Work type:Master's thesis/paper
Typology:2.09 - Master's Thesis
Organization:FERI - Faculty of Electrical Engineering and Computer Science
Abstract:Zaradi porasta in kompleksnosti kibernetskih groženj postajajo tradicionalni pristopi k zaznavanju napadov manj učinkoviti. Algoritmi strojnega učenja z zmožnostjo hitre obdelave velike količine podatkov ponujajo napredne rešitve za zaznavanje in preprečevanje vedno bolj prikritih in kompleksnih groženj. Namen magistrskega dela je bil ugotoviti, katere metode strojnega učenja so najučinkovitejše pri zaznavi napadov izvidništva in naprednih trajnih groženj – kompleksnejših vrst kibernetskih napadov. Raziskali smo, kako ustrezna predpriprava podatkov vpliva na učinkovitost napovedi in koliko je ansambelski pristop pri tem učinkovitejši. S sistematičnim pregledom literature smo ugotovili, da so pri zaznavi kompleksnih groženj najučinkovitejši algoritmi XGBoost, LightGBM, odločitvena drevesa, naključni gozd in naivni Bayesov klasifikator. Omenjene algoritme smo vključili v eksperiment, v katerem smo metode s pomočjo metrik (točnost, natančnost, priklic in F1 vrednost) ovrednotili. Ugotovili smo, da je pri klasifikaciji napadov najučinkovitejši algoritem naključni gozd. Iste algoritme smo vključili tudi v ansambel, pri čemer smo ugotovili, da je pri zaznavi naprednih trajnih groženj in izvidništva ansambelski pristop učinkovitejši, saj dosega višje rezultate vseh štirih metrik. Z ustreznimi tehnikami predpriprave podatkov pa smo dokazali, da ta pomembno vpliva na končno učinkovitost modelov oz. ansambla.
Keywords:kibernetska varnost, napredne trajne grožnje, izvidništvo, strojno učenje
Place of publishing:Maribor
Publisher:[M. Rotovnik]
Year of publishing:2025
PID:20.500.12556/DKUM-92909 New window
UDC:004.85:004.056.5(043.2)
COBISS.SI-ID:244041475 New window
Publication date in DKUM:08.07.2025
Views:264
Downloads:106
Metadata:XML DC-XML DC-RDF
Categories:KTFMB - FERI
:
Copy citation
  
Average score:(0 votes)
Your score:Voting is allowed only for logged in users.
Share:Bookmark and Share



Hover the mouse pointer over a document title to show the abstract or click on the title to get all document metadata.

Licences

License:CC BY-NC-ND 4.0, Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International
Link:http://creativecommons.org/licenses/by-nc-nd/4.0/
Description:The most restrictive Creative Commons license. This only allows people to download and share the work for no commercial gain and for no other purposes.
Licensing start date:25.05.2025

Secondary language

Language:English
Title:Machine learning-based detection of complex cyber threats
Abstract:As the number and complexity of cyber threats grow at an increasing pace, traditional approaches to attack detection are becoming less effective. Machine learning algorithms, with their ability to quickly process vast amounts of data, offer advanced solutions for detecting and preventing increasingly covert and complex threats. The aim of this master's thesis was to determine which machine learning methods are most effective in detecting reconnaissance attacks and advanced persistent threats – more complex types of cyberattacks. We examined how proper data preprocessing impacts prediction effectiveness and to what extent ensemble methods improve accuracy. Through a systematic literature review, we found that the most effective algorithms for detecting complex threats are XGBoost, LightGBM, decision trees, random forest, and the naive Bayes classifier. We included these algorithms in our own experiment, where we evaluated the methods using metrics such as accuracy, precision, recall, and F1 score, and found that the most effective algorithm for classifying attacks was random forest. We also incorporated these algorithms into an ensemble, where we discovered that, for detecting advanced persistent threats and reconnaissance, the ensemble approach is more effective than individual methods, achieving higher scores across all four metrics. Furthermore, we demonstrated that proper data preprocessing significantly impacts the final performance or the models or ensemble.
Keywords:cybersecurity, advanced persistent threats, reconnaissance, machine learning


Comments

Leave comment

You must log in to leave a comment.

Comments (0)
0 - 0 / 0
 
There are no comments!

Back
Logos of partners University of Maribor University of Ljubljana University of Primorska University of Nova Gorica