Skip to main navigation Skip to search Skip to main content

Near realtime attack detections with Weka Framework

Research output: Book chapter/Published conference paperConference paperpeer-review

Abstract

Cybersecurity has been a volatile and growing issue in using the Internet for business, communications, marketing, and social presence, for over 30 years, requiring constant alert protection from cyber-attacks. That is why it is important for all our systems to develop and implement good monitoring tools, which can detect data breaches and other forms of cyber-attacks from threat actors in near real time. Adversaries attack mostly from the Dark Web because it is the only web layer where users can act anonymously. However not all Distributed Denial of Service (DDoS), ransomware, botnet, and other attack types are performed through the Dark Web. That is why we need a monitoring system, which can detect all attack types from various online locations. In this paper we present a simple experimental approach with the use of appropriate Machine Learning (ML) techniques to detect attacks from network packets, which are grabbed via NetworkMiner. We used the Weka Framework to perform our monitoring actions in near real time. The authors deliberately chose the Weka Framework, a freeware tool with ML techniques to detect anomalies, which can be used by Small and Medium Enterprises (SMEs) quite efficiently to monitor illegal activities. NetworkMiner can also be used as freeware, but if an SME needs more details about network packets, then it costs almost $US1000. These two tools can be combined to provide an efficient low-cost entry level way to monitor a network system as the SME migrates towards the “near real-time detection” state where.
Original languageEnglish
Title of host publicationProceedings of the Third International Conference on Advances in Computing Research (ACR'25)
EditorsKevin Daimi, Abeer Al Sadoon
Place of PublicationSwitzerland
PublisherSpringer
Pages331-345
Number of pages15
Volume1346
ISBN (Electronic)9783031876479
ISBN (Print)9783031876462
DOIs
Publication statusPublished - Apr 2025
Event3rd International Conference on Advances in Computing Research: ACR'25 - Radisson Nice Airport Hotel, Nice, France
Duration: 07 Jul 202509 Jul 2025
https://iicser.org/ACR25/
https://doi.org/10.1007/978-3-031-87647-9 (Proceedings)
https://iicser.org/ACR25/images/ACR25_Program.pdf (Program)

Publication series

NameLecture Notes in Networks and Systems
Volume1346 LNNS
ISSN (Print)2367-3370
ISSN (Electronic)2367-3389

Conference

Conference3rd International Conference on Advances in Computing Research
Country/TerritoryFrance
CityNice
Period07/07/2509/07/25
OtherWelcome to the 2025 International Conference on Advances in Computing Research (ACR’25). This conference is organized by the Institute for Innovations in Computer Science and Engineering Research (IICSER). The goal of this conference is to bring together researchers from academia, business, industry, and government to exchange significant and innovative contributions and research ideas and to act as a platform for international research collaboration. To this extent, ACR’25 is seeking submissions that furnish innovative ideas, techniques, methodologies and applications. ACR’25 is currently composed of seven tracks.
The 2025 International Conference on Advances in Computing Research (ACR’25) will be composed of research paper presentations, keynote speeches, panels, special sessions, workshops and tutorials. All accepted and registered papers will be published in the conference Proceedings and indexed. The Proceedings will be published by Springer Book Series: Lecture Notes in Networks and Systems, and indexed by SCOPUS, DBLP, INSPEC, Norwegian Register for Scientific Journals and Series, SCImago, WTI Frankfurt eG, and zbMATH.
Internet address

Fingerprint

Dive into the research topics of 'Near realtime attack detections with Weka Framework'. Together they form a unique fingerprint.

Cite this