Intrusion detection in secure shell using Multilayer Perceptron
Abstract
As the use of Internet users increases, their inter-connectivity enables malicious users to exploit resources and surge Internet attacks. The increasing Internet attacks pose various difficult challenges to develop flexible, adaptive, reliable security-focused approaches. An Intrusion Detection System (IDS) is the most essential components being used to detect Internet attacks. An intrusion detection system is a system which monitors, analyzes, and detects the events that are considered as violation to the security policies of a networked environment. Even encrypted protocols are violated, Secure Shell server can be an appropriate repository to launch brute-force attacks, distribute spam messages, and assess new malware. The traffic of encrypted protocols like SSH makes packet payload examination challenging and slow. In flow monitoring techniques, flows in aggregated network data are observed. Data flow is a set of packets that passes in a certain time interval and that has a similar set of attributes. CICIDS2017 is used in this research of intrusion detection techniques. Analysis of data set with respect to four classes, which are BENIGN and SSH-Patator, in which all data attributes can be categorized. A predictive model which uses an idea of detecting intrusion in a network is capable of recognizing intrusions or attacks as "1" and normal connections as “0” using Multilayer Perceptron (MLP) classification.