KMITL

Permanent URI for this communityhttps://dspace.kmitl.ac.th/handle/123456789/1

Browse

Search Results

Now showing 1 - 8 of 8
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Evaluation of Machine Learning Techniques for Denial-of-Service Attack Detection in Digital Information Exchange
    (2026-01-01)
    Suwimol, Piyapol
    ;
    Chimmanee, Krishna
    ;
    Pomsathit, Auttapon
    Anomaly detection plays a critical role in mitigating cybersecurity threats, particularly Distributed Denial of Service (DDoS) attacks. This study evaluates the performance of tree-based and ensemble learning models, including Decision Tree, Random Forest, and XGBoost, for classifying Snort log data, alongside the application of Isolation Forest for time-series anomaly detection. The experiments were conducted using ICMP-based Ping Flood attacks in a controlled network environment, with data collected from Snort intrusion detection system logs. The classification results indicate that XGBoost achieved the highest performance, with 99.81% accuracy, 99.93% precision, 99.65% recall, and 99.79% F1-score under a 70–30 train-test split. Random Forest and Decision Tree also demonstrated strong performance, while Logistic Regression showed lower effectiveness due to its limitations in modeling nonlinear patterns. For anomaly detection, Isolation Forest was applied to time-series data collected over a 19-day period. The model detected 93 anomaly points, of which 41 overlapped with Wireshark-confirmed events. However, a false positive rate of 41.67% was observed, indicating the need for parameter tuning to balance detection sensitivity and operational efficiency. Overall, the findings demonstrate that ensemble-based learning approaches, particularly XGBoost, are effective for detecting DDoS-related patterns within the experimental setting. However, the results are limited to ICMP-based attack scenarios in a controlled environment. Further validation, including cross-validation, multi-attack evaluation, and deployment-level performance analysis, is required to assess generalizability and practical applicability.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Adaptive Detection of Advanced Persistent Threats (APT) With Graph Neural Networks and Rehearsal-Based Continual Learning on Wazuh EDR Telemetry
    (2025-01-01)
    Pomsathit, Auttapon
    In the rapidly evolving cybersecurity landscape, Advanced Persistent Threats (APTs) pose major challenges due to their stealthy and adaptive behavior. Traditional detection methods based on signatures or heuristics are limited in identifying novel and evolving attacks, while static deep learning models suffer from concept drift and catastrophic forgetting, leading to degraded performance over time. This paper proposes an adaptive APT detection framework that integrates Graph Neural Networks (GNNs) with rehearsal-based continual learning using telemetry data from Wazuh, an open-source Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platform. Endpoint telemetry is represented as graphs where nodes denote system components and edges describe behavioral interactions among them. Experimental evaluations on real-world Wazuh telemetry augmented with sandbox-executed APT scenarios demonstrate that the proposed approach consistently achieves F1-scores above 0.98, outperforming static and fine-tuned baselines in both adaptability and knowledge retention. These results confirm that combining graph-based representations with continual learning offers a scalable, interpretable, and resilient solution for modern SOC and EDR environments facing advanced and evolving cyber threats.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Overcoming Concept Drift and Catastrophic Forgetting: Designing and Evaluating Deep Learning Architectures for Behavioral Malware Detection using Sysmon Data
    (2025-01-01)
    Thaibkhuang, Surapit
    ;
    Laungwilawan, Sorawit
    ;
    Pomsathit, Auttapon
    ;
    Ruangdech, Suppanat
    ;
    Pongpisutsopa, Suchittra
    In dynamic cybersecurity environments, traditional signature-based malware detection systems struggle to identify novel threats due to their reliance on static patterns. This study proposes a deep learning-based approach for behavioral malware detection using Sysmon logs, addressing two critical challenges: concept drift and catastrophic forgetting. The main contribution lies in a comprehensive comparative evaluation of four neural architectures CNN-only, CNN-BiLSTM with and without attention were evaluated alongside two continual learning strategies: fine-tuning and rehearsal. Experimental results demonstrate that fine-tuning enhances adaptability to new threats but severely degrades performance on previously learned data. In contrast, rehearsal-based incremental learning effectively mitigates forgetting while maintaining high detection accuracy across evolving datasets. Hybrid models incorporating attention mechanisms showed superior robustness. These findings underscore the importance of combining suitable neural architectures with continual learning techniques to build resilient and adaptive Endpoint Detection and Response (EDR) systems capable of handling real-world malware evolution. Future work includes collecting comprehensive real-world behavioral datasets, applying advanced continual learning strategies and exploring Graph Neural Networks or Transformers to improve detection robustness and adaptability.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Denial of Service Attack Detection in Digital Information Exchange by Using ML Techniques
    (2024-01-01)
    Suwimol, Piyapol
    ;
    Pomsathit, Auttapon
    ;
    Chimmanee, Krishna
    Denial of Service attack detection plays a significant role in the field of digital information exchange security, and log messages recording detailed system runtime information has become an important data analysis object accordingly. To improve traditional detection technology, several anomaly detection mechanisms, particularly the machine learning method, have been presented in recent years. This research proposes a technique for detecting anomalies in web log files that uses two machine learning algorithms. Isolation Forest is used to generate a set of features targeting traditional, while XGBoost is a tree-based model used for classification. The experimental data comes from the real web server for digital information exchange environment where log files have been collected, which contain many true intrusion messages. After comparing with two types of machine learning algorithms used in anomaly detection, testing results for this data set indicate that this system has a greater detection accuracy and can detect unknown anomaly data.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Analysis of Cybersecurity Vulnerabilities in Maritime GNSS Systems
    (2024-01-01)
    Chinnarong, Thirawat
    ;
    Pomsathit, Auttapon
    ;
    Yongsiriwit, Karn
    The maritime industry is increasingly dependent on Global Navigation Satellite Systems (GNSS) such as GPS, GLONASS, BeiDou, and Galileo for navigation and operational efficiency. However, these systems are vulnerable to cyber threats like spoofing and jamming, which can severely disrupt maritime operations by misleading navigation systems [1], [2]. This study analyzes the cybersecurity vulnerabilities of GNSS systems used in maritime environments, utilizing a Software-Defined Radio (SDR) to simulate GNSS spoofing attacks on various maritime GNSS receivers [3]. The findings reveal that all tested receivers are susceptible to spoofing attacks, underscoring the need for enhanced cybersecurity measures [4]. The study advocates for the development of advanced detection systems, improved signal authentication, and adherence to cybersecurity guidelines provided by organizations such as INTERTANKO and the International Maritime Organization (IMO) [5], [6]. The proposed strategies aim to mitigate the risks associated with GNSS vulnerabilities and ensure the safety and security of maritime operations.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    The design of linear and circular polarization for dual band microstrip slot antenna
    (2014-01-01)
    Pomsathit, Auttapon
    ;
    Rakluea, Paitoon
    ;
    Anantrasirichai, Noppin
    ;
    Benjangkaprasert, Chawalit
    ;
    Wakabayashi, Toshio
    This paper presents a lightweight antenna for wireless communication systems. The proposed antenna has been designed to be a dual-band and dual-polarized antenna by using a right-angled slot structure fed a by microstrip line. The designed antenna is composed of three right-angled slot radiators on the ground plane. The first two radiators are right-angled slots of similar scale which are added to generate circular polarization at 4.95 GHz, while the last one has been designed for linear polarization at 2.45 GHz. Furthermore, in order to achieve dual-band operation and dual polarization with good matching, a special arrangement is proposed. The results of simulation and measurements such as return loss, axial ratio, and radiation patterns are shown at the resonant frequencies of 2.45 and 4.95 GHz. Details of the experimental results are presented and discussed. In addition, the presented antenna can operate and cover the applications of a wireless local area network (WLAN IEEE 802.11 a/b/g/j/n). © 2014 Institute of Electrical Engineers of Japan.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Performance analysis of channel effective for wireless LAN and wireless ad-hoc networks
    (2008-12-01)
    Pomsathit, Auttapon
    ;
    Nakasuwan, Jintana
    ;
    Lorphichian, Aekkarat
    ;
    Benjangkaprasert, Chawalit
    Wireless local area networks (WLANs) provide mobility and convenience to users, the efficiency of today's WLANs are still far from satisfactory. In this paper discusses the performance of WLANs and wireless Ad-Hoc networks, our main contribution is analyze several methods to compare the throughput performance on simulation and experimental results. We describe NS-2 (Network Simulation) implementations for fine-tuning WLAN and wireless Ad-Hoc network parameters such as the physical layer (IEEE802.ll) datalink layer (MAC) and network layer (Routing Protocol) related parameters. Customizing these parameters oppose to using the values specified in the standards will increase throughput and channel utilization under fixed load conditions.
  • Some of the metrics are blocked by your 
    Item type:Publication,
    Performance analysis of space diversity for OFDM transmission
    (2008-12-01)
    Lorphichian, Aekkarat
    ;
    Pomsathit, Auttapon
    ;
    Nakasuwan, Jintana
    ;
    Srikalsin, Thanupong
    ;
    Benjangkaprasert, Chawalit
    This paper presents a simple space diversity scheme for orthogonal frequency-division multiplexing (OFDM) transmission. Using multiple antenna technology provides the same diversity order as maximal-ratio receiver combining (MRRC). It is also shown that the scheme may easily be generalized to M transmit antennas and M receive antennas to provide a diversity order of 2M. We examine feasibility of several types of OFDM transmitter diversity techniques and generate data for the third-generation wireless systems. In particular, single input single output (SISO), single input multiple output (SIMO), multiple input single output (MISO), and multiple input multiple output (MIMO) techniques are compared. We employ the long range AWGN channel to enable transmitter diversity.