02SECURITY ANALYSIS / ACADEMIC PROJECT

SSH Shell Attack Classification.

Honeypot shell-command data, MITRE ATT&CK characterization, and machine-learning methods to classify attacks and examine attacker behavior.

Conceptual workflow: shell-command observations, data preparation, model analysis, and interpretation.
01THE QUESTION

Problem & context

Shell commands captured by an SSH honeypot contain evidence of attacker behavior. This coursework explored how data preparation and machine-learning methods could support attack classification and interpretation.

02THE INVESTIGATION

Approach

01

Prepare the observations

Preprocessing and exploratory analysis worked with honeypot shell-command data.

02

Characterize attack behavior

MITRE ATT&CK provided a framework for describing attack patterns, alongside classification and clustering work.

03

Train and interpret

Participation in ML/deep-learning training, fine-tuning, and feature-importance analysis used PyTorch and Scikit-learn.

03WHAT THE WORK SHOWS

Supported outcomes

  • An academic implementation and analysis of shell-command attack classification.
  • Repository notebooks and scripts cover preprocessing, exploration, classification, and clustering, with result and report artifacts.
  • Feature-importance analysis supported examination of the signals associated with attacker behavior.
04THE PROJECT MATERIAL

Artifacts & scope

  • Preprocessing and exploration notebooks
  • Classification and clustering scripts
  • Result and report artifacts
Explore the project repository (opens in a new tab)
SCOPE OF THE WORK

Coursework, rather than a production detection system. No validated accuracy, dataset-scale, generalization, or operational effectiveness claim is made. The work is presented as project participation, without attributing every component to an individual.

GET IN TOUCH

Let’s start a conversation.

For professional opportunities, research conversations, or a thoughtful exchange about security and computing.