Digital twin-enabled intelligent attack detection mechanisms for autonomous networks

Yükleniyor...
Küçük Resim

Tarih

Bölüm / Program

Computer Engineering Programme

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Graduate School

Özet

In parallel with the increasing number of internet users and technological advancements, there has been a corresponding surge in cyberattacks targeted at internet services. Consequently, safeguarding services from cyber threats has become crucial for organizations. Digital-twin (DT) technology has gained considerable attention due to its numerous advantages in various industries, including real-time monitoring and control in manufacturing, risk assessment in industry, and predictive maintenance in the aerospace sector. It is expected to have a significant influence in developing "self-X" capabilities and "zero-touch" operations and maintenance in 6G networks. DT allows for performance testing, real-time network monitoring, quick simulation, and optimization, which maximize its potential in the network domain. Furthermore, it enhances the cost-efficiency of evaluation, prediction, and optimization processes compared to physical systems. However, despite its many benefits, the DT potential is yet to be widely explored for network anomaly detection. Over the last few years, the importance of next-generation networks has received increasing recognition due to the growing demand for efficiency and the large volume of data. With the advent of intelligent infrastructure and facilities, the authorities have recently focused on cyber-security, making it a primary concern. While traditional security solutions can help safeguard the systems from harmful entities, they do not provide enough transparency for security researchers to learn about attackers' behaviors. Distributed denial of service (DDoS) attack solutions currently cannot manage vast amounts of aggregated data rates. Therefore, they are unsuited to the core networks of Internet service providers (ISPs). In the same way, the current intrusion detection mechanisms are insufficient to detect external attacks, making it challenging to handle them effectively for seaport networks. This thesis proposes two intelligent detection mechanisms for ISP core and seaport networks to solve attack detection problems and provide autonomous network characteristics. The first mechanism is TwinCoNet, a DT-enabled detection system for autonomous ISP core networks that uses online learning and the YANG paradigm. TwinCoNet is designed to handle highly aggregated data rates and uses an Automated Feature Selection module (AutoFS) to identify the most suitable features for each router, enabling independent operation for each router. The second mechanism is TwinPot, a DT-assisted honeypot designed to handle external attacks in smart seaports. The proposed intelligent attack detection mechanism uses DT technology for internal attacks and the Automated Classification Method (AutoCM) to categorize various forms of attacks. The performance of both mechanisms is tested using extensive datasets. Results from the first mechanism reveal that the proposed system effectively identifies the attacks, adjusts the feature selection technique, and estimates the attack within fifteen minutes of it commencing, with an accurate categorization rate of ninety-seven percent. On the other hand, the second mechanism findings demonstrate that our approach successfully detects simultaneous internal and external attacks on the system and changes the classification technique. Overall, this study highlights and demonstrates the potential of DT technology in enhancing cyber-security solutions for critical infrastructures such as ISP core networks and seaports.

Tanım

Thesis (M.Sc.) -- İstanbul Technical University, Graduate School, 2023

Dergi veya Seri

ISSN

ISBN

Haklar

Anahtar Kelimeler

Digital twin, Attack detection mechanisms, Autonomous networks

Alıntı

Onay

Gözden geçir

Tamamlayıcı Bilgiler

Referans Gösteren

0

Views

0

Downloads