Skip to content

D6.2 Initial version of the synthetic datasets for cyber intelligence using fair Machine Learning

[featured_image]
  • Version
  • Download 6
  • File Size 2.93 MB
  • File Count 1
  • Create Date 29 de August de 2023
  • Last Updated 18 de July de 2024

D6.2 Initial version of the synthetic datasets for cyber intelligence using fair Machine Learning

The D6.2 report centers on the development of a Simulator for incidents that employs fair machine learning in the realm of cyber-intelligence, specifically for testing anomaly and intrusion detection systems. The core objective is to utilize large pre-trained language models to generate malicious packet flow mutations based on actual attack traffic, thereby enhancing the attack detection rates of Network-based Intrusion Detection systems. Specifically, we have developed a method for generating synthetic traffic that mimics a cyber-attack and triggers alerts on the IDS dashboard, as well as serve as input for training anomaly detection models. We have also developed methods to replay packets on targeted IDS systems. The report introduces the initial version of the incident simulator and details the development of four modules: (1) Threat Emulation Tool, which creates adversarial traffic for baseline and accuracy evaluation, (2) Artificial Data Engine, which uses a transformer-based model to create synthetic packets, (3) PCAP Factory, a CLI utility to integrate synthetic packet generation into existing workflows, and (4) PCAP Shipper, that contains replay methods for delivering synthetic packets to designated endpoints.