Research examining the security of network intrusion detection systems is vital for protecting modern digital infrastructure from increasingly sophisticated threats. This study investigates how machine learning network security models, trained with tactical frameworks like MITRE ATT&CK, respond to adversarial examples crafted through black-box optimization techniques. Using three attack algorithms, HopSkipJump, Simultaneous Perturbation Stochastic Approximation Attack and the Square Attack algorithms, we demonstrate that the Random Forest model remains vulnerable despite tactical framework integration. For example, the HopSkipJump attack achieved a 92% success rate in causing malicious traffic to appear benign. Our analysis reveals which network traffic features are most susceptible to manipulation, with model performance metrics declining significantly under adversarial conditions. These findings highlight an important gap between theoretical security frameworks and practical implementation that must be addressed to develop more robust defense systems. By identifying specific vulnerabilities, this research contributes valuable insights that can inform improved adversarial robustness in operational network security environments.
Files and links (1)
url
RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled DataView
Published (Version of record) link to article Open CC BY V4.0
Related links
Details
Title
RandomForestNN Classification for Adversarial AI Black-Box Techniques on MITRE ATT&CK Labeled Data