Anomaly detection through User Behaviour Analysis

The rise in cyber-attacks and cyber-crime is causing more and more organizations and individuals to consider the correct implementation of their security systems. The consequences of a security breach can be devastating, ranging from loss of public confidence to bankruptcy. Traditional techniques fo...

Descripción completa

Detalles Bibliográficos
Autor: Dumitrasc, Valentina
Tipo de recurso: tesis de maestría
Fecha de publicación:2023
País:España
Institución:Universitat Politècnica de Catalunya (UPC)
Repositorio:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglés
OAI Identifier:oai:upcommons.upc.edu:2117/394877
Acceso en línea:https://hdl.handle.net/2117/394877
Access Level:acceso abierto
Palabra clave:Computer security
Malware (Computer software)
Machine learning
cybersecurity
malware
machine learning
antivirus
Seguretat informàtica
Aprenentatge automàtic
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
id ES_dcd90fae6bdccaba27538a8dbd90765a
oai_identifier_str oai:upcommons.upc.edu:2117/394877
network_acronym_str ES
network_name_str España
repository_id_str
spelling Anomaly detection through User Behaviour AnalysisDumitrasc, ValentinaComputer securityMalware (Computer software)Machine learningcybersecuritymalwaremachine learningantivirusSeguretat informàticaAprenentatge automàticÀrees temàtiques de la UPC::Informàtica::Seguretat informàticaThe rise in cyber-attacks and cyber-crime is causing more and more organizations and individuals to consider the correct implementation of their security systems. The consequences of a security breach can be devastating, ranging from loss of public confidence to bankruptcy. Traditional techniques for detecting and stopping malware rely on building a database of known signatures using known samples of malware. However, these techniques are not very effective at detecting zero-day exploits because there are no samples in their malware signature databases. The limitation of not being able to detect zero-day exploits leaves organisations vulnerable to new and evolving malware threats. To address this challenge, this thesis proposes a novel approach to malware detection using machine learning techniques. The proposed approach creates a user profile that trains a machine learning model using only normal user behaviour data, and detects malware by identifying deviations from this profile. In this way, the proposed approach can detect zero-day malware and other previously unknown threats without having a specific database of malware signatures. The proposed approach is evaluated using real-world datasets, and different machine learning algorithms are compared to evaluate their performance in detecting unknown threats. The results show that the proposed approach is effective in detecting malware, achieving high accuracy and low false positive rates. This thesis contributes to the field of malware detection by providing a new perspective and approach that complements existing methods, and has the potential to improve the overall security of organisations and individuals in the face of evolving cybersecurity threats.Universitat Politècnica de CatalunyaSerral Gracià, René20232023-06-0820232023-10-11master thesishttp://purl.org/coar/resource_type/c_bdccNAhttp://purl.org/coar/version/c_be7fb7dd8ff6fe43info:eu-repo/semantics/masterThesisapplication/pdfhttps://hdl.handle.net/2117/394877reponame:UPCommons. Portal del coneixement obert de la UPCinstname:Universitat Politècnica de Catalunya (UPC)Inglésengopen accesshttp://purl.org/coar/access_right/c_abf2info:eu-repo/semantics/openAccessoai:upcommons.upc.edu:2117/3948772026-05-27T15:37:01Z
dc.title.none.fl_str_mv Anomaly detection through User Behaviour Analysis
title Anomaly detection through User Behaviour Analysis
spellingShingle Anomaly detection through User Behaviour Analysis
Dumitrasc, Valentina
Computer security
Malware (Computer software)
Machine learning
cybersecurity
malware
machine learning
antivirus
Seguretat informàtica
Aprenentatge automàtic
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
title_short Anomaly detection through User Behaviour Analysis
title_full Anomaly detection through User Behaviour Analysis
title_fullStr Anomaly detection through User Behaviour Analysis
title_full_unstemmed Anomaly detection through User Behaviour Analysis
title_sort Anomaly detection through User Behaviour Analysis
dc.creator.none.fl_str_mv Dumitrasc, Valentina
author Dumitrasc, Valentina
author_facet Dumitrasc, Valentina
author_role author
dc.contributor.none.fl_str_mv Serral Gracià, René
dc.subject.none.fl_str_mv Computer security
Malware (Computer software)
Machine learning
cybersecurity
malware
machine learning
antivirus
Seguretat informàtica
Aprenentatge automàtic
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
topic Computer security
Malware (Computer software)
Machine learning
cybersecurity
malware
machine learning
antivirus
Seguretat informàtica
Aprenentatge automàtic
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
description The rise in cyber-attacks and cyber-crime is causing more and more organizations and individuals to consider the correct implementation of their security systems. The consequences of a security breach can be devastating, ranging from loss of public confidence to bankruptcy. Traditional techniques for detecting and stopping malware rely on building a database of known signatures using known samples of malware. However, these techniques are not very effective at detecting zero-day exploits because there are no samples in their malware signature databases. The limitation of not being able to detect zero-day exploits leaves organisations vulnerable to new and evolving malware threats. To address this challenge, this thesis proposes a novel approach to malware detection using machine learning techniques. The proposed approach creates a user profile that trains a machine learning model using only normal user behaviour data, and detects malware by identifying deviations from this profile. In this way, the proposed approach can detect zero-day malware and other previously unknown threats without having a specific database of malware signatures. The proposed approach is evaluated using real-world datasets, and different machine learning algorithms are compared to evaluate their performance in detecting unknown threats. The results show that the proposed approach is effective in detecting malware, achieving high accuracy and low false positive rates. This thesis contributes to the field of malware detection by providing a new perspective and approach that complements existing methods, and has the potential to improve the overall security of organisations and individuals in the face of evolving cybersecurity threats.
publishDate 2023
dc.date.none.fl_str_mv 2023
2023-06-08
2023
2023-10-11
dc.type.none.fl_str_mv master thesis
http://purl.org/coar/resource_type/c_bdcc
NA
http://purl.org/coar/version/c_be7fb7dd8ff6fe43
dc.type.openaire.fl_str_mv info:eu-repo/semantics/masterThesis
format masterThesis
dc.identifier.none.fl_str_mv https://hdl.handle.net/2117/394877
url https://hdl.handle.net/2117/394877
dc.language.none.fl_str_mv Inglés
eng
language_invalid_str_mv Inglés
language eng
dc.rights.none.fl_str_mv open access
http://purl.org/coar/access_right/c_abf2
dc.rights.openaire.fl_str_mv info:eu-repo/semantics/openAccess
rights_invalid_str_mv open access
http://purl.org/coar/access_right/c_abf2
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.publisher.none.fl_str_mv Universitat Politècnica de Catalunya
publisher.none.fl_str_mv Universitat Politècnica de Catalunya
dc.source.none.fl_str_mv reponame:UPCommons. Portal del coneixement obert de la UPC
instname:Universitat Politècnica de Catalunya (UPC)
instname_str Universitat Politècnica de Catalunya (UPC)
reponame_str UPCommons. Portal del coneixement obert de la UPC
collection UPCommons. Portal del coneixement obert de la UPC
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869421806466629632
score 15.301603