Related Experiment Video
Updated: Aug 23, 2025

Monitoring On-Target Signaling Responses in Larval Zebrafish - Z-REX Unmasks Precise Mechanisms of Electrophilic Drugs and Metabolites
Published on: June 2, 2023
Detecting Reconnaissance and Discovery Tactics from the MITRE ATT&CK Framework in Zeek Conn Logs Using Spark's
Sikha Bagui1, Dustin Mink1, Subhash Bagui2
1Department of Computer Science, University of West Florida, Pensacola, FL 32514, USA.
This study introduces UWF-ZeekData22, a new dataset for network intrusion detection. Machine learning classifiers were evaluated for effectiveness and scalability in identifying cyber threats using big data analytics.
Area of Science:
- Computer Science
- Cybersecurity
- Data Science
Background:
- The increasing complexity and volume of network traffic necessitate advanced intrusion detection systems (IDS).
- Existing intrusion detection datasets may lack relevance to current cyber threats, impacting the effectiveness of machine learning models.
- Scalability and real-time performance are critical challenges for modern IDS.
Purpose of the Study:
- To introduce and utilize the novel UWF-ZeekData22 dataset for network intrusion detection research.
- To evaluate the performance, scalability, and response time of various machine learning classifiers on this new dataset.
- To analyze the effectiveness of these classifiers in detecting reconnaissance and discovery tactics within network data.
Main Methods:
- Development and utilization of the UWF-ZeekData22 dataset, comprising Zeek Connection Logs from Security Onion 2.
- Labeling of the dataset using the MITRE ATT&CK framework's Tactics, Techniques, and Procedures (TTPs).
- Application of multiple machine learning classifiers (naïve Bayes, random forest, decision tree, support vector classifier, gradient boosted trees, logistic regression) using the Spark big data framework.
Main Results:
- Performance evaluation of several machine learning classifiers on the UWF-ZeekData22 dataset.
- Analysis of the scalability and response times of these classifiers when processed using Spark.
- Identification of effective classifiers for detecting specific network intrusion tactics like reconnaissance and discovery.
Conclusions:
- The UWF-ZeekData22 dataset provides a relevant and contemporary resource for IDS research.
- Machine learning classifiers, when implemented with big data frameworks like Spark, show promise for scalable network intrusion detection.
- Further research can leverage this dataset to develop more robust and efficient intrusion detection systems.
More Related Videos
08:13SwarmSight: Real-time Tracking of Insect Antenna Movements and Proboscis Extension Reflex Using a Common Preparation and Conventional Hardware
Published on: December 25, 2017
11:09Use of MALDI-TOF Mass Spectrometry and a Custom Database to Characterize Bacteria Indigenous to a Unique Cave Environment Kartchner Caverns, AZ, USA
Published on: January 2, 2015
Related Concept Videos
Mass Analyzers: Overview
Mass Analyzers: Common Types
Peptide Identification Using Tandem Mass Spectrometry
This technique helps gather information regarding the protein from which the peptide was obtained and to study the peptides’ amino acid sequence. Identifying peptides from a complex mixture is an important component of the growing field of...
Leaky Scanning