Utilize este identificador para referenciar este registo: http://hdl.handle.net/20.500.11960/4311
Título: Exploring the role of unsupervised machine learning for anomaly detection in active directory logins
Autores: Magalhães, João
Malta, Silvestre
Sousa, Bruno Miguel de
Palavras-chave: Active directory
Anomaly detection
Machine learning
Data: 3-Dez-2024
Resumo: Active Directory (AD) stores information about objects on the network and makes this information easy for administrators and users to find and use. Due to its widespread use in recent times, it has become a target for various types of attacks. The objective of AD attacks, or attacks on any identity administration infrastructure, is pretty simple: to gain the highest access in the shortest time possible. Regardless of the source of the attack or the point of intrusion, attackers are always looking to escalate privileges. To increase the anomaly detection in AD, it is intended to apply Machine Learning (ML) mechanisms on the same, reducing false positives and detecting more attacks. To do so, a dataset has been created that contains relevant information on AD access. This dataset has been created and combined with logs generated in an experimental setup environment according to the differentiated cases generated. Then, Unsupervised Machine Learning (UML) was used to identify abnormal events that could signify AD attacks.
Descrição: Mestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelo
URI: http://hdl.handle.net/20.500.11960/4311
Aparece nas colecções:ESTG - Dissertações de mestrado

Ficheiros deste registo:
Ficheiro Descrição TamanhoFormato 
Bruno_Sousa.pdf3.45 MBAdobe PDFVer/Abrir


Todos os registos no repositório estão protegidos por leis de copyright, com todos os direitos reservados.