Please use this identifier to cite or link to this item:
http://hdl.handle.net/20.500.11960/4311| Title: | Exploring the role of unsupervised machine learning for anomaly detection in active directory logins |
| Authors: | Magalhães, João Malta, Silvestre Sousa, Bruno Miguel de |
| Keywords: | Active directory Anomaly detection Machine learning |
| Issue Date: | 3-Dec-2024 |
| Abstract: | Active Directory (AD) stores information about objects on the network and makes this information easy for administrators and users to find and use. Due to its widespread use in recent times, it has become a target for various types of attacks. The objective of AD attacks, or attacks on any identity administration infrastructure, is pretty simple: to gain the highest access in the shortest time possible. Regardless of the source of the attack or the point of intrusion, attackers are always looking to escalate privileges. To increase the anomaly detection in AD, it is intended to apply Machine Learning (ML) mechanisms on the same, reducing false positives and detecting more attacks. To do so, a dataset has been created that contains relevant information on AD access. This dataset has been created and combined with logs generated in an experimental setup environment according to the differentiated cases generated. Then, Unsupervised Machine Learning (UML) was used to identify abnormal events that could signify AD attacks. |
| Description: | Mestrado em Cibersegurança na Escola Superior de Tecnologia e Gestão do Instituto Politécnico de Viana do Castelo |
| URI: | http://hdl.handle.net/20.500.11960/4311 |
| Appears in Collections: | ESTG - Dissertações de mestrado |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| Bruno_Sousa.pdf | 3.45 MB | Adobe PDF | View/Open |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

