A hybrid layered architecture for detection and analysis of network based Zero-day attack

Saurabh Singh, Pradip Kumar Sharma, Seo Yeon Moon, Jong Hyuk Park

Research output: Contribution to journalArticlepeer-review

5 Scopus citations

Abstract

A Zero-day (0-day) susceptibility is an undisclosed computer software or application vulnerability that could be exploited to affect hardware, applications, data, or networks negatively. The main objectives of a Zero-day attack are for hackers or attackers to be able steal sensitive information, legal documents, enterprises data, and other information. We have analyzed the lifecycle of Zero-day vulnerabilities and different detection methodologies. In this paper, we propose a novel hybrid layered architecture framework for Zero-day attack detection and analysis in real-time, which is based on statistics, signatures, and behavior techniques.  To enhance our architecture, we used an SVM approach in order to provide unsupervised learning and minimize false alarm detection capabilities.

Original languageEnglish
Pages (from-to)100-106
Number of pages7
JournalComputer Communications
Volume106
DOIs
StatePublished - 1 Jul 2017

Keywords

  • Anomaly behavior
  • Exploit
  • Support vector machine
  • Zero-day attacks

Fingerprint

Dive into the research topics of 'A hybrid layered architecture for detection and analysis of network based Zero-day attack'. Together they form a unique fingerprint.

Cite this