Using honeynet data and a time series to predict the number of cyber attacks
Computer Science and Information Systems, Tome 18 (2021) no. 4.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

A large number of cyber attacks are commonly conducted against home computers, mobile devices, as well as servers providing various services. One such prominently attacked service, or a protocol in this case, is the Secure Shell (SSH) used to gain remote access to manage systems. Besides human attackers, botnets are a major source of attacks on SSH servers. Tools such as honeypots allow an effective means of recording and analysing such attacks.However, is it also possible to use them to effectively predict these attacks? The prediction of SSH attacks, specifically the prediction of activity on certain subjects, such as autonomous systems, will be beneficial to system administrators, internet service providers, and CSIRT teams. This article presents multiple methods for using a time series, based on real-world data,to predict these attacks. It focuses on the overall prediction of attacks on the honeynet and the prediction of attacks from specific geographical regions. Multiple approaches are used, such as ARIMA, SARIMA, GARCH, and Bootstrapping. The article presents the viability, precision and usefulness of the individual approaches for various areas of IT security.
Keywords: cyber attacks, honeynet, honeypot, SSH, time series, prediction
@article{CSIS_2021_18_4_a5,
     author = {Matej Zuz\v{c}\'ak and Petr Bujok},
     title = {Using honeynet data and a time series to predict the number of cyber attacks},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {18},
     number = {4},
     year = {2021},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2021_18_4_a5/}
}
TY  - JOUR
AU  - Matej Zuzčák
AU  - Petr Bujok
TI  - Using honeynet data and a time series to predict the number of cyber attacks
JO  - Computer Science and Information Systems
PY  - 2021
VL  - 18
IS  - 4
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2021_18_4_a5/
ID  - CSIS_2021_18_4_a5
ER  - 
%0 Journal Article
%A Matej Zuzčák
%A Petr Bujok
%T Using honeynet data and a time series to predict the number of cyber attacks
%J Computer Science and Information Systems
%D 2021
%V 18
%N 4
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2021_18_4_a5/
%F CSIS_2021_18_4_a5
Matej Zuzčák; Petr Bujok. Using honeynet data and a time series to predict the number of cyber attacks. Computer Science and Information Systems, Tome 18 (2021) no. 4. http://geodesic.mathdoc.fr/item/CSIS_2021_18_4_a5/