In this work, we explore what constitutes an effective intrusion detection of cyberattacks in the context of modern cyberthreats and open research problems. We discuss the important properties of real-world networks and show that they have a significant impact on the performance of intrusion detection systems and prevent the industrial adoption of solutions proposed in academic literature. This research is centred around the OpTC dataset, which is the largest and most realistic among the existing IDS datasets. We discuss the importance of this dataset and the reasons why it remains relatively obscure. In order to make it more accessible to future research, we perform an in-depth analysis and demonstrate how this dataset accurately reflects some of the constraints of real-world networks. We conclude that it can help design and evaluate practical intrusion detection systems.
Our contributions include a description of the dataset, a baseline evaluation, and a deterministic labelling algorithm that converts the ground truth document into a set of labels suitable for conventional machine learning applications. The released labels can be used in future research, saving the need to repeat this difficult and time-consuming process. Additionally, we show that the attacks in this dataset can be detected using relatively simple anomaly detection methods, which highlights the need for better metrics for evaluating IDS.
Using these results, we propose a detection method based on a critical insight into the structure of operations in a modern SOC. The resulting two-stage IDS framework serves as a proof-of-concept that the requirements of the security teams and important constraints of the real-world enterprise networks can be effectively integrated into the IDS design. This work shows that by focusing on the correct problems and requirements, it is possible to reduce the gap between academic goals and the needs of the industry. However, although the results of this research are very promising, several problems remain open for future research, including reducing dependency on the closed-world assumption of the training data and scaling up end-to-end pipeline performance.
| Date | 28 Apr 2025 |
|---|
| Original language | French |
|---|
| Awarding Institution | - École de technologie supérieure
|
|---|
| Supervisor | Chamseddine Talhi (Supervisor) |
|---|
Nikulshin, V. (Author),
Talhi (Supervisor),
28 Apr 2025Student thesis: Master's thesis › Master in Engineering: Engineering