Showing posts with label Dos and Ddos. Show all posts
Showing posts with label Dos and Ddos. Show all posts

Sunday, September 13, 2026

Detecting Zero-Day Cyberattacks with Deep Reinforcement Learning: An Open-Set Intrusion Detection Approach | Research Work

 Hi everyone, I am posting something on this blog after a decade. Good to see that my 11-year-old posts are still getting some views and is still somehow relevant even in the age of AI.... 

Sharing my research work here, as it is linked to cybersecurity and zero-day attacks. Thanks!


Abstract: 

Open-Set Intrusion Detection and Semantic Analysis of Zero-Day Network Attacks Using Deep Reinforcement Learning and Large Language Models

by Shreyash Tiwari

The increasing prevalence of zero-day cyberattacks presents a significant challenge for modern Intrusion Detection Systems (IDS), as previously unseen network traffic often falls outside the distribution of supervised training data. Traditional deep learning-based IDS solutions operate under a closed-set assumption, requiring all attack categories to be known during training.

Consequently, novel attacks may be misclassified as benign traffic or incorrectly assigned to known attack classes, reducing the effectiveness of network defense mechanisms. Although recent open-set recognition approaches improve the detection of unknown traffic, they typically provide limited insight into the behavioral characteristics of detected anomalies, requiring additional manual investigation by security analysts.

This thesis presents a unified framework for open-set intrusion detection and semantic analysis of unknown network traffic by combining deep learning, reinforcement learning, and large language models. The proposed framework employs a Convolutional Neural Network (CNN) to learn feature representations from known network traffic classes and a Deep Q-Network (DQN) that uses SoftMax-derived uncertainty metrics, including maximum probability, probability gap, and Shannon entropy, to dynamically distinguish known from unknown traffic without manually defined confidence thresholds. To improve interpretability, a selective Large Language Model (LLM) reasoning module is applied only to traffic identified as unknown by the CNN-DQN pipeline. Unlike existing approaches that focus solely on detection or apply computationally expensive LLM reasoning across all traffic, the proposed framework combines efficient open-set detection with targeted semantic interpretation of suspicious network behavior.

Experimental evaluation was conducted using the CICIDS-2017 and UNSW-NB15 intrusion detection datasets. The CNN-DQN framework achieved a binary F1-score of 97.83% for known-versus-unknown traffic separation while maintaining strong performance on known attack classes and effectively identifying previously unseen attacks. Cross-dataset experiments demonstrated the framework’s ability to generalize to traffic distributions not observed during training. The LLM-assisted reasoning stage generated behaviorally aligned explanations for 77.5% of DQN-flagged unknown traffic samples and provided meaningful behavioral insights for an additional 22.1% of samples, demonstrating its effectiveness in supporting contextual interpretation of suspicious network activity.

The proposed framework contributes to the development of adaptive, explainable, and deployable intrusion detection systems capable of addressing evolving cyber threats. By combining uncertainty-aware open-set detection with semantic reasoning, the system enables security analysts, network administrators, and cybersecurity researchers to not only identify previously unseen attacks but also understand their underlying behavioral characteristics. This capability can support faster incident response, improved threat intelligence generation, and enhanced protection of enterprise, cloud, Internet of Things (IoT), and critical infrastructure environments against emerging cyber threats.


DOI: https://doi.org/10.62791/20638 


Research Gate: https://www.researchgate.net/profile/Shreyash-Tiwari-6

Sunday, September 13, 2026 by Shreyash Tiwari · 0

Friday, May 4, 2012

|| How to shut-down big websites using dos | Anonymous toolkit [LOIC] ||

hi guys wats? up! here is a Anonymous Dos  (Denial-of service attack) toolkit .

you can shut-down websites for specific timing usin g

 this toolkit very effective for hackerzzz it is a toolkit
by anonymous !


here are things required:

  • 1) insert url of website with (http://)
  •  2)set power of attack
  • 3)hit "IMMA CHARGIN MAH LAZER"

here is a screenshot:


LOIC 1.0.0.0 Toolkit Download:  Here 
LOIC 1.1.1.17 Save As (LOGIC.EXE) FULL Toolkit Download:
 Here


i hope you like this tutorial and this toolkit.
provide your FeeDBack....!! :D

Friday, May 4, 2012 by Shreyash Tiwari · 0

Sunday, April 29, 2012

|| Jani-dos || powerful (Dos/Ddos) toolkit ||

Ddos?

A 
denial-of-service attack (DoS attack) or distributed denial-of-service attack (DdoS attack) is an attempt to make a computer or network resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the efforts of one or more people to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet. 


work of this Ddos?

In a typical DdoS attack, a hacker  begins by exploiting a vulnerability in one computer system and making it the DdoS master. It is from the master system that the intruder identifies and communicates with other systems that can be compromised. The intruder loads cracking tools available on the Internet on multiple  sometimes thousands of compromised systems. With a single command, the intruder instructs the controlled machines to launch one of many flood attacks against a specified target. The inundation of packets to the target causes a denial of service.

this Ddos tool coded on visual basic 6 firstly you must send this ocx's to system32



comdlg32.ocx
msinet.ocx
mscomctl.ocx
mswinsck.ocx

this Tool will be detected supicious by Antiviruses because ddos tool works on port 80 & it is also a backdoor port soo it is a false positive detection dont worry this tool is clean.




                                                                 

           JANI-DOS:  DOWNLOAD HERE 


i hope you get some tips! askz if any
problemzzz..!! 

Sunday, April 29, 2012 by Shreyash Tiwari · 0

crash websites with Ddos Attack using command prompt | dos manually

how to  ddos a website using command prompt just follow simple steps:


1.Find  a target website , mainly the one  with apache server 

for ex we have our website : www.targetwebstie.com

2.Now we have to find ip adress of website so, goto run>typ CMD >then  type ping  www.targetwebsite.com 

3.now you will find the ip adress of website below just copy that ip adress let it for ex : 100.00.0.0

4.Now we have got ip adress to send the packets , now in the next line  type :


ping 100.00.0.0  -t -l 65500
[Here ip adress is just an example]

now keep your computer as it is for 1 hour


5.after one hour visit the website you will see the website is crashed 

hope u like this post :D:D

by Shreyash Tiwari · 0

Friday, April 13, 2012

Hacking with Anti-Android Toolkit | Full Tutorial

Here is tut for android users like, i am a andro user :)!

Features:


Scan - This will scan the selected target for open ports and vulnerabilities, also allowing the user to select a specific scanning script for a more advanced/targeted scan.

Spy - This will 'sniff' images transferred to/from the selected device and display them on your phone in a nice gallery layout. If you choose a network subnet/range as target, then all images transferred on that network - for all connected devices - will be shown. Another feature of the Spy plugin is to sniff URLs (web sites) and non-secured (ie, not HTTPS) username/passwords logins, shown on the bottom drawer.

D.O.S - This will cause a Denial Of Service (D.O.S) for the selected target, ie. it will deny them any further access to the internet until you exit the attack.

Replace images - This will replace all images transferred to/from the target with an Anti logo, thus preventing from attacked used seeing any images on their browsers while the browse the Internet, except for a nice looking Anti logo...

M.I.T.M - The Man In The Middle attack (M.I.T.M) is an advanced attack used mainly in combination with other attack. It allows invoking specific filters to manipulate the network data. Users can also add their own mitm filters to create more mitm attacks.

Attack - This will initiate a vulnerability attack using our Cloud service against a specific target. Once executed successfully, it will allow the attack to control the device remotely from your phone.

Report - This will generate a vulnerability report with findings, recommendations and tips on how to fix found vulnerabilities or bad practices used.




lets go! guyz!
Go to http://www.zImperium.com/anti.html and follow the instructions there. You will receive a download link to your email. Open this link from your smartphone and then install the app as instructed. (Make sure that 3rd Party Applications is enabled in Settings->Applications->Unknown Sources.)
iOS users can join the list of upcoming (public) BETA testers in the same page, by clicking on the Apple icon.

initial_login
On each run, ANTI will prompt to map the connected network, and when done, it will suggest scanning it for known vulnerabilities and misconfiguration on the targets found. Once a vulnerable target (to remote attacks) is found, it will be marked with red stamp and will appear on the report as a vulnerable device. Displayed in the report is the issue (e.g : MS08-067), how to solve the issue (Windows Update) and how to defend from similar threats in the future (Block port 445 on firewall).

windows-box-vulnerable-gd2-black
We start by mapping the network - ANTI will scan and detect devices connected to the network. Each device will be displayed with a suitable icon identifying its hardware type and/or the operating system. We can then further scan for vulnerabilities on each of the devices found.
MAC-Circle

Now that we have our available targets displayed, we can choose any of them to try and penetrate, connect, or sniff network traffic.

The sniffer captures network traffic and displays images, URL’s, user/password combinations, and cookies - all this is collected from the target in real-time, and displayed on ANTI for viewing and examining. We can click on any of the URL’s/cookies to visit the same site our target is visiting.

ANTI also allows us to connect to open ports on the targets, also displaying the opened ports that were found on previous scans. 

ports
After playing a bit with the app, I feel comfortable enough to try and penetrate one of my computers, running Windows7 or Mac OS X that are updated only to 1 month prior to this report. I choose the target and click ‘Penetrate CSE’. This plug-in is injecting javascript code using MiTM into target's traffic and redirect traffic to a URL serving Client Side Exploit. Once the target got exploited, ANTI reveals several functions that can be executed over the exploited target: Send screenshot of the current desktop, execute command. The controller functionality is implemented in a very easy-to-use and fun (!) way, allowing both advanced users and home-users to understand the risks of the found vulnerability - while zImperium censored any real possibility to cause real damage to the target, they allow basic information gathering and real life demos such as ejecting the CD-ROM, or grabbing a screenshot (for the assessment’s final report).
attack-menu


I decided to try the password-cracker on my router. I then realized (the good old hard way) that I better change my password ASAP since it took ANTI less than 30 seconds to crack! Next I executed the cracker on my target running a SQL server and, lo and behold, ANTI didn’t discover the passwords - due to use of high complexity passwords. These results were enough to get me to (finally!) change my router’s password.

There are additional functionalities built into ANTI, such as a unique and fully functional HTTP server that allows publishing files on your device, as well as uploading files to the device, visual traceroute using google-maps, and more. 

cracked_pass
Once we are done testing, the most important ANTI function is the Report - Everything we have found in the network, vulnerable devices, opened ports, and extra information that will later assist when preparing the assessment report - all is summed up in text and emailed. ANTI3 supports multiple networks so now you can fully use it for your daily penetration tests.

Friday, April 13, 2012 by Shreyash Tiwari · 0

Wednesday, April 4, 2012

Ddos Attack with Backtrack 5 using Slowloris.pl | shutdown big websites

INTRO:
hey guys today i will provide you a backtrack Ddos tut to shut-down big websites yes you can shut down big websites with this tut you just need 5-6 computers  so u can say this tut is so powerful i hav provided a picture tut hope u all like it 

Ddos website manually..!

ADVICE: {use anonymous proxie} protect yourself from getting caught :P 

MATERIAL REQUIRED:


>> slowloris.pl script
>> Backtrack 5r1 or r2


PICTURE TUTORIAL:

                           create a new folder name "slowloris.pl"




                     now  paste slowloris.pl (perl) script in the folder



                                              now move the folder to desktop 


                                            open the target folder 


enter the following script in your folder and replace your website url with "websitehere.com"


click enter and if the following page appears that means your attack works your target website will shut-down :):)!!

h0pe you all like this tutorial...!!

Wednesday, April 4, 2012 by Shreyash Tiwari · 1

PHP Ddos attack script | Free download |

one of the advanced Tool of website crashing known as PHP Ddos attack script like i say all my post are only for educational purpose so enjoy this software at your own riskzzzz.. don't blame this blog 

FUNCTIONS :


ddos script
php dos
php ddos script
php dos script
ddos php script
ddos script php
phpDos
ddos scripts
script DDOS
php ddos
ddos php
denial of service script
dos php
ddos attack script
php ddoser
script php ddos
dos php script
php script ddos
ddos script download
php DDos attack script
script ddos php
PHP DoS Script by Exe
ddos
php dos by exe
ddos skript
mysql ddos
DENIAL OF SERVICE php script
php ddos attack
php ddos download
download script ddos
ddos online
denial of service scripts
PHP DoS/DDoS (Denial Of Service) Script
ddos php tool
php curl ddos
ddos php scripts
script ddos attack
dos script denial
php Dos scripts
php denial of service




Mirror 1:

Script download here: download script {11.1 MB}

Mirror 2:


full script download: download scripT {26.3 MB}

by Shreyash Tiwari · 1

Saturday, March 31, 2012

How To crash websites with rDos | throug ip hacking technique...!!! | Full [TUT]

hello guyzzzz.. i found way to crash websites. but like i say my post are only for knowledge purpose.Have you ever wanted to DOS attack on a website. Here I am going to write about a tool which is really helpful but it wouldn't be effective on big servers. 

read more »

Saturday, March 31, 2012 by Shreyash Tiwari · 0

Wednesday, March 28, 2012

Ddos Attack on websites keep a website offline for some time | with Ddos Toolkit QSloloris v0.1

hi THERE i will tell u How To some specific time-period this tutorial is by Shreyash Tiwari only for educational purpose

                                         DoS Attack?
Short form of denial-of-service attack, a type of attack on a network that is designed to bring the network to its knees by flooding it with useless traffic. Many DoS attacks, such as the Ping of Death and Teardrop attacks, exploit limitations in the TCP/IP protocols. For all known DoS attacks, there are software fixes that system administrators can install to limit the damage caused by the attacks. But, like viruses, new DoS attacks are constantly being dreamed up by hackers.first check that your website vul apache server website or not for that go there - http://uptime.netcraft.com/


now search the url of your website check the result like shown in the screenshot:

                                                 
                     so our website is vulnerable!! :D:D!!

                     now download this Dos toolkit:

                    Qslowloris download  {4.27 MB}

                     virus scan of Qslowloris {safe}

 now after downloading extend the Qslowloris in your desktop  and do the same like i am doing                                         
                                  see screenshot:                                                                       

      

click on Fire ! the website will be Shut down for specific time according to your Timeout limit :D:D!!

Wednesday, March 28, 2012 by Shreyash Tiwari · 0

Tuesday, March 27, 2012

|| Ddos Attack using anonymous toolkit || High orbit ion cannon [HOIC] ||

Ddos?
A denial-of-service attack (DoS attack) or distributed denial-of-service attack (DdoS attack) is an attempt to make a computer or network resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of the efforts of one or more people to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet.Perpetrators of DoS attacks typically target sites or services hosted on high-profile web servers such as banks, credit card payment gateways, and even root name servers. The term is generally used relating to computer networks, but is not limited to this field; for example, it is also used in reference to CPU resource management.


 this is a powerful Ddos toolkit by anonymous.


  • enter values by clicking on THREADS 
  • then choose target in the right corner of tool. click on "+"option enter website url ok.
  •  then click on "FIRE TEH LAZER"



over :D

                       



Download Here [6.42 MB]


if the attack works the website will shut down

Tuesday, March 27, 2012 by Shreyash Tiwari · 0

All Rights Reserved TeCh ZoNe | Blogger Template by Bloggermint
back to top