[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120801-en":3,"doc-seo-120801-105":30,"detail-sidebar-cat-0-en-105":90},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120801,8796095360427,"Lucas Martin","https://ap-avatar.wpscdn.com/davatar_994ba38a5ba835b3df7d355c54d3ed8d",8,"Research & Report","Analyzing and Reporting Network Intrusion Using Machine Learning","This disclosure presents automated techniques for detecting network intrusions and generating responses using machine learning. Internet-connected (or other network-connected) devices are monitored for malicious activity, and intrusion patterns are identified with machine-learned models trained for intrusion detection. The threat actor’s source IP address is then determined, and public IP ownership information is used to identify the appropriate party to report abuse to. The party is notified and instructed to stop the malicious activity.","Technical Disclosure Commons  \nDefensive Publications Series  \nAugust 2023  \nAnalyzing and Reporting Network Intrusion Using Machine Learning  \nn/a  \nFollow this and additional works at: [https://www.tdcommons.org/dpubs_series](https://www.tdcommons.org/dpubs_series)  \nRecommended Citation  \nn/a, \"Analyzing and Reporting Network Intrusion Using Machine Learning\", Technical Disclosure Commons,(August 08, 2023)  \n[https://www.tdcommons.org/dpubs_series/6121](https://www.tdcommons.org/dpubs_series/6121)  \nThis work is licensed under a Creative Commons Attribution 4.0 License.  \nThis Article is brought to you for free and open access by Technical Disclosure Commons. It has been accepted for inclusion in Defensive Publications Series by an authorized administrator of Technical Disclosure Commons.  \nAnalyzing and Reporting Network Intrusion Using Machine Learning  \nABSTRACT  \nThis disclosure describes automated detection of network intrusion and generating a response based on machine learning techniques. Devices connected to the internet (or other network) are monitored for malicious activity. Patterns of intrusion are detected using machinelearned models that are trained for intrusion detection. The source IP address of the threat actor is identified. Using publicly available IP-address ownership information, the appropriate  \nindividual or entity to report abuse to is identified. The individual or entity is notified of  \nmalicious activity and a demand is made that such activity cease.  \nKEYWORDS  \n● Network intrusion  \n● Intrusion detection  \n● Intrusion attempt  \n● Malicious activity  \n● Abuse report  \n● Machine learning  \n● Intrusion pattern  \nBACKGROUND  \nIt is burdensome for operators of networks or autonomous systems to review, analyze, respond to, and report incidents that involve malicious threat actors attempting to access or abuse network or internet resources. Although tools exist to alert users to the abuse of network  \nresources, set up honeypots, and protect users, sending abuse reports requires manual  \nPublished by Technical Disclosure Commons, 2023 2  \nintervention and/or review. Manual intervention or review is a slow and tedious process that can delay the response to intrusion attempts.  \nDESCRIPTION  \nFig. 1: Analyzing and reporting network intrusion using machine learning  \nThis disclosure describes network intrusion detection and response techniques that utilize machine learning to reduce or eliminate the need for manual intervention or review. As  \nillustrated in Fig. 1, devices connected to the internet (or other network) are monitored for  \nmalicious activity (102). For example, such devices may be part of a corporate network that is  \nbeing secured using the described techniques.  \nPatterns of intrusion are detected (104). Detection of patterns may be performed using  \nmachine-learned models that are trained to detect network intrusions. The source internet  \nprotocol (IP) address of the threat actor is identified (106). Using publicly available IP-address  \nownership information, the appropriate individual or entity to report abuse to is identified (108)  \n[https://www.tdcommons.org/dpubs_series/6121](https://www.tdcommons.org/dpubs_series/6121) 3  \nautomatically. The individual or entity is notified of malicious activity and a demand is made  \nthat such activity cease (110) .  \nCONCLUSION  \nThis disclosure describes automated detection of network intrusion and generating a response based on machine learning techniques. Devices connected to the internet (or other network) are monitored for malicious activity. Patterns of intrusion are detected using machinelearned models that are trained for intrusion detection. The source IP address of the threat actor is identified. Using publicly available IP-address ownership information, the appropriate  \nindividual or entity to report abuse to is identified. The individual or entity is notified of  \nmalicious activity and a demand is made that such activity cease. ","cbCaidXql9CCM6Y8","https://ap.wps.com/l/cbCaidXql9CCM6Y8","pdf",124403,1,4,"English","en",105,"# Abstract\n# Background\n# Description\n## Fig. 1\n# Conclusion\n# References","[{\"question\":\"What does the disclosure automate for network intrusion handling?\",\"answer\":\"It automates detection of network intrusion patterns and generates a response by identifying the threat actor’s source IP and notifying the appropriate party to report abuse.\"},{\"question\":\"How are intrusion patterns detected in this approach?\",\"answer\":\"Intrusion patterns are detected using machine-learned models trained specifically for intrusion detection.\"},{\"question\":\"How is the abuse reporting target selected?\",\"answer\":\"The approach uses publicly available IP-address ownership information to identify the appropriate individual or entity to report abuse to.\"}]","Analyzing and Reporting Network Intrusion Using Machine Learning | PDF",1785732097,10,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":85,"head_meta":87,"extra_data":89,"updated_unix":28},"analyzing-and-reporting-network-intrusion-using-machine-learning","",{"@graph":36,"@context":84},[37,53,67],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":21},"https://docshare.wps.com/document/analyzing-and-reporting-network-intrusion-using-machine-learning/120801/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":61,"encodingFormat":60,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":64,"interactionType":65,"userInteractionCount":4},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70,76,80],{"name":71,"@type":72,"acceptedAnswer":73},"What does the disclosure automate for network intrusion handling?","Question",{"text":74,"@type":75},"It automates detection of network intrusion patterns and generates a response by identifying the threat actor’s source IP and notifying the appropriate party to report abuse.","Answer",{"name":77,"@type":72,"acceptedAnswer":78},"How are intrusion patterns detected in this approach?",{"text":79,"@type":75},"Intrusion patterns are detected using machine-learned models trained specifically for intrusion detection.",{"name":81,"@type":72,"acceptedAnswer":82},"How is the abuse reporting target selected?",{"text":83,"@type":75},"The approach uses publicly available IP-address ownership information to identify the appropriate individual or entity to report abuse to.","https://schema.org",{"og:url":52,"og:type":86,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":88,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":91},[92,96,100,104,109,114,119,122,127,130,133],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":93,"show_sort_weight":94,"slug":95},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":97,"show_sort_weight":98,"slug":99},"Literature",80,"literature",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},"Exam",70,"exam",{"id":105,"doc_module":4,"doc_module_name":46,"category_name":106,"show_sort_weight":107,"slug":108},5,"Comic",60,"comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":29,"doc_module":4,"doc_module_name":46,"category_name":131,"show_sort_weight":29,"slug":132},"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":46,"category_name":135,"show_sort_weight":105,"slug":136},19,"General","general"]