Predicting the Next Step of a Multistep Network Attacks During Capture the Flag Events Using LSTM

C. Antonia Severin, P. Claudio Canales, Romina Torres

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

DEFCON, the world's largest cybersecurity conference, hosts a highly competitive 'Capture the Flag' (CTF) competition, renowned for being one of the longest and most challenging in the cybersecurity community. This event typically spans three days and features the top 20 teams globally, each tasked with defending their systems while attacking others. During these events, teams have limited time to patch their services and develop exploits before engaging with other teams to capture their flags. The fast-paced nature of DEFCON CTF events means that success often hinges on the team's experience and agility. Teams face concurrent attacks from multiple opponents and have constrained resources, making it impossible to address all threats simultaneously. In this work, we propose leveraging long short-term memory (LSTM) neural networks to predict the next steps of concurrent multi-stage and multi-step network attacks (MSNAs). This approach aims to enhance team performance by enabling informed decision-making and efficient resource allocation. We extracted attack data from pcap files of CTFs provided by DEFCON, encompassing approximately 300 iterations per CTF. The model was trained on 80% of the initial iterations and validated on the remaining 20%, where more sophisticated behaviors and refined strategies are anticipated. Our methodology achieved a prediction accuracy over 80%, significantly improving response strategies and allowing teams to prioritize threats effectively.

Original languageEnglish
Title of host publication2024 43rd International Conference of the Chilean Computer Science Society, SCCC 2024
PublisherIEEE Computer Society
ISBN (Electronic)9798331527891
DOIs
StatePublished - 2024
Externally publishedYes
Event43rd International Conference of the Chilean Computer Science Society, SCCC 2024 - Temuco, Chile
Duration: 28 Oct 202430 Oct 2024

Publication series

NameProceedings - International Conference of the Chilean Computer Science Society, SCCC
ISSN (Print)1522-4902

Conference

Conference43rd International Conference of the Chilean Computer Science Society, SCCC 2024
Country/TerritoryChile
CityTemuco
Period28/10/2430/10/24

Keywords

  • CTF
  • LSTM
  • MSNA
  • cybersecurity

Fingerprint

Dive into the research topics of 'Predicting the Next Step of a Multistep Network Attacks During Capture the Flag Events Using LSTM'. Together they form a unique fingerprint.

Cite this