Technical details about the detected attacks and classification rules.
The system utilizes a hybrid detection engine combining Behavioral Analysis and Random Forest Classification. Below are the 11 specific attack types currently identified by the system, along with their detection logic and triggering thresholds.
Denial of Service attack that consumes server resources by initiating many connections without completing the handshake.
Detection Rule:
Overwhelms the target with ICMP Echo Request (Ping) packets.
Detection Rule:
Reconnaissance activity to identify open ports and services on a target system.
Detection Rule:
Layer 7 DDoS attack aimed at web servers and applications.
Detection Rule:
Reflection attack using open DNS resolvers to flood a target with large responses.
Detection Rule:
Repeated attempts to guess SSH credentials.
Detection Rule:
Scanning for exposed Remote Desktop Protocol services.
Detection Rule:
Scanning for exposed Windows file sharing services (often used by ransomware).
Detection Rule:
Abnormal broadcast traffic in Industrial Control Systems (ICS/OT).
Detection Rule:
Anomalous high-frequency requests in SCADA/ICS networks.
Detection Rule:
Reflection attack utilizing Network Time Protocol servers.
Detection Rule: