摘要: |
A method for detecting a cyberattack is provided. A set ofpacket capture training data has data elements labeled as beingnormal or cyberattack data. Metrics in the data are identifiedthat are associated with either cyberattack data or normal data.Statistical measures are developed from these metrics. Thetraining data and statistical measures are used to train amachine learning network. Real packet capture data is obtainedand statistical measures are developed for this real data. Thetrained machine learning network, real data and real statisticalmeasures are utilized to classify the real data as cyberattackdata or normal data. Users are alerted if the trained machinelearning data identifies cyberattack data in the real packetcapture data. |