MétaCan
Menu
Back to cohort
Record W7010495940

Implementación de un servicio de detección de ataques de denegación de sistemas

2024· dissertation· es· W7010495940 on OpenAlexaboutno aff

Bibliographic record

VenueUPM Digital Archive (Technical University of Madrid) · 2024
Typedissertation
Languagees
FieldComputer Science
TopicNetwork Security and Intrusion Detection
Canadian institutionsnot available
Fundersnot available
KeywordsWork (physics)Control (management)SAFERPanel data
DOInot available

Abstract

fetched live from OpenAlex

Los ataques DDoS (Denial of Service) han sido una amenaza persistente en el ciberespacio desde la década de 1990, y su sofisticación y frecuencia han ido en aumento. Estos ataques implican la saturación maliciosa de recursos de red o sistemas informáticos, lo que resulta en la interrupción del servicio para usuarios legítimos. Esta actividad no solo representa un problema económico para las empresas, sino que, cuando los objetivos son infraestructuras críticas como las de comunicaciones o sanitarias, estos ataques pueden utilizarse como métodos de desestabilización. En la actualidad, discernir si una conexión es legítima o no es complicado. Los sistemas pueden enfrentar dificultades para manejar el volumen del tráfico generado en estos ataques y tienden a generar falsos positivos, bloqueando así conexiones legítimas. El objetivo de este trabajo es recopilar datos, limpiarlos y prepararlos, desarrollar un modelo de deep learning capaz de detectar estas conexiones y luego implementar y desplegar el modelo en la nube pública. En la primera parte del trabajo, se exploran los conjuntos de datos CIC-DDoS2019 y CIC-IDS2017 del Canadian Institute for Cybersecurity. Se eliminan y corrigen valores atípicos y se seleccionan variables utilizando técnicas como Random Forest y la importancia de variables para reducir la dimensionalidad del conjunto de datos. Posteriormente, se implementa y entrena una red FNN siguiendo la arquitectura ResNet. En la segunda sección, se desarrolla un panel de control que permite visualizar un informe de las conexiones después de pasar por el modelo. Este panel se despliega en la nube de AWS, junto con un backend que proporciona información a la página web y otros mecanismos para la limpieza de datos y la recopilación en tiempo real. Abstract: DDoS (Denial of Service) attacks have been a persistent threat in cyberspace since the 1990s, with their sophistication and frequency steadily increasing. These attacks involve the malicious saturation of network resources or computer systems, resulting in service disruption for legitimate users. This activity not only poses an economic problem for businesses but when the targets are critical infrastructures such as communication or healthcare systems, these attacks can be used as destabilization methods. Currently, discerning whether a connection is legitimate or not is challenging. Systems may struggle to handle the volume of traffic generated in these attacks and tend to produce false positives, thus blocking legitimate connections. The objective of this work is to collect data, clean and prepare it, develop a deep learning model capable of detecting these connections, and then implement and deploy the model in the public cloud. In the first part of the work, datasets such as CIC-DDoS2019 and CIC-IDS2017 from the Canadian Institute for Cybersecurity are explored. Outliers are removed and corrected, and variables are selected using techniques like Random Forest and variable importance to reduce the dimensionality of the dataset. Subsequently, a FNN network following the ResNet architecture is implemented and trained. In the second section, a control panel is developed that allows visualization of a report of connections after passing through the model. This panel is deployed on the AWS cloud, along with a backend that provides information to the webpage and other mechanisms for real-time data cleaning and collection.

Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.

How this classification was reachedexpand

Full frame machine prediction

Teacher imitation

Not calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.

metaresearch head score (Codex)0.006
metaresearch head score (Gemma)0.017
Version: metacan-v3-hybrid-931329e0061cValidation status: machine_predicted_unvalidated
Candidate categoriesnone
Consensus categoriesnone
DomainCandidate signal: none · Consensus signal: none
Study designCandidate signal: Simulation or modeling · Consensus signal: none
GenreCandidate signal: Empirical · Consensus signal: Empirical
Teacher disagreement score0.016
Threshold uncertainty score0.031

Distilled classifier scores by category (both heads)

CategoryCodexGemma
Metaresearch0.0060.017
Meta-epidemiology (narrow)0.0010.001
Meta-epidemiology (broad)0.0010.001
Bibliometrics0.0010.001
Science and technology studies0.0010.001
Scholarly communication0.0040.004
Open science0.0030.003
Research integrity0.0020.003
Insufficient payload (model declined to judge)0.0070.002

Machine scores (provisional)

The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.

Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.

Opus teacher head0.007
GPT teacher head0.224
Teacher spread0.217 · how far apart the two teachers sit on this one work
Validation statusscore_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from it

Classification

machine, unvalidated

Machine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.

The models applied no category: nothing in the taxonomy fit this work.
Study designSimulation or modeling
Domainnot available
GenreEmpirical

How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".

Quick stats

Citations0
Published2024
Admission routes1
Has abstractyes

Explore more

Same venueUPM Digital Archive (Technical University of Madrid)Same topicNetwork Security and Intrusion DetectionFrench-language works237,207