Skip to main content

Advances, Systems and Applications

Table 2 Top decision rules for 'label'

From: Next-generation cyber attack prediction for IoT systems: leveraging multi-class SVM and optimized CHAID decision tree

Rule ID

Rule

Mode category

Record count

Record percentage

Rule confidence

76

Bwd IAT Std >  = 2.000, & BwdPkt Len Std <  = 3.000 &InitBwd Win Byts >  = 2& InitBwd Win Byts < 3 SYN Flag Cnt <  = 2 & Tot FwdPkts <  = 3

Brute_Force

24,204

26.8

100.0

57

Flow IAT Min < 4 & Bwd IAT Min < 1 & Pkt Len Std < 1.000 & Flow Duration < 2 & Tot FwdPkts < 2

Brute_Force

16,841

18.7

99.7

56

Flow IAT Min < 3 & Bwd IAT Min < 1 & Pkt Len Std < 1.000 & Flow Duration < 2 & Tot FwdPkts < 2

Brute_Force

8,348

9.3

95.3

5

SYN Flag Cnt <  = 2 & Tot FwdPkts < 1

Port_Scan

7,107

7.9

99.9

72

Fwd IAT Min >  = 2 & TotLenFwdPkts <  = 3 & Flow IAT Mean >  = 5.000 & SYN Flag Cnt < 1 &

Tot FwdPkts <  = 3

Normal

6,427

7.1

99.9