Temporal Dynamics of AI-Driven Cyberattacks: Timing-Based Detection and Sub-Second Defense Against Autonomous Attack Agents
收藏资源简介:
The data were collected from a multiprotocol honeypot deployment comprising ten service types spanning network protocols (SSH, RDP, SMB), applications (database, web server, email), and cloud-native attack surfaces (container orchestration and ICS/SCADA). Over the collection period, the environment recorded 40,153 unsolicited attack events from 327 distinct source IP addresses, encompassing approximately 8,400 attacker sessions, 8,437 captured commands, and more than 155,000 attempted credential pairs. The study characterizes the timing signatures of AI-agent-like attack sessions across the full reconnaissance-to-exploitation pathway and validates a behavioral detection rubric against known ground truth in a blinded, four-arm controlled experiment (ROC-AUC 0.970 overall; 0.964 against delay-matched scripted bots).



