SSH Shell Attack Classification.
Honeypot shell-command data, MITRE ATT&CK characterization, and machine-learning methods to classify attacks and examine attacker behavior.
Problem & context
Shell commands captured by an SSH honeypot contain evidence of attacker behavior. This coursework explored how data preparation and machine-learning methods could support attack classification and interpretation.
Approach
Prepare the observations
Preprocessing and exploratory analysis worked with honeypot shell-command data.
Characterize attack behavior
MITRE ATT&CK provided a framework for describing attack patterns, alongside classification and clustering work.
Train and interpret
Participation in ML/deep-learning training, fine-tuning, and feature-importance analysis used PyTorch and Scikit-learn.
Supported outcomes
- An academic implementation and analysis of shell-command attack classification.
- Repository notebooks and scripts cover preprocessing, exploration, classification, and clustering, with result and report artifacts.
- Feature-importance analysis supported examination of the signals associated with attacker behavior.
Artifacts & scope
- Preprocessing and exploration notebooks
- Classification and clustering scripts
- Result and report artifacts
Coursework, rather than a production detection system. No validated accuracy, dataset-scale, generalization, or operational effectiveness claim is made. The work is presented as project participation, without attributing every component to an individual.