Lab6 - Basic Probability

Course: INF-604: Data Analysis I
Lecturer: Sothea HAS, PhD



Objective: In this lab, you will learn how to


1. Basic Probability with Cybersecurity Intrusion Dataset

We will work with Kaggle’s Cybersecurity Intrusion Dataset available here. Start by importing the data into your working environment. Then answer the following questions.

# To do: Import the data from kaggle

A. Data Inspection:

  • Load the dataset and inspect its structure (dimension).
  • Identify quantitative and qualitative columns. Modify column types if necessary. Quick summary statistics for each type.
  • Detect outliers and take note of columns with outliers.
  • Inspect missing values in all columns of the dataset. As the missing values represent a state of the column where the accesses are not encripted, we simply denote those missing values by not_encripted instead of imputing them.
# To do

B. We assume that each activity in this data is indepeependent. If a traffic is chosen at random from this dataset, estimate the following probability:

B.1. Univariate Information:

  1. The chosen traffic uses AES encryption.
  2. The chosen traffic uses unknown browser type.
  3. The chosen traffic occurs during unusual time access.
  4. The chosen traffic has tried to login more than 6 times.
  5. The chosen traffic has been detected as an attack.
# To do

B.2. Bivariate Information:

  1. The chosen traffic uses AES encryption and occurs during unusual time access.
  2. The traffic uses an unknown browser type and detected as an attack.
  3. The traffic has tried to login less than 4 times and detected as an attack.
  4. The traffic has tried to login more than 6 times and detected as an attack.
  5. The traffic is an attack or attempted to login more than 8 times.
# To do

B.2. Conditional Information:

  1. Knowing that a traffic occurs during unusual time access, what is the probability that it’s an attack?
  2. What’s the probability that it’s an attack given that it uses AES encryption?
  3. If a traffic has tried to login more than 6 times, what’s the chance that it’s an attack?
  4. What’s the probability that it’s an attack given that it uses an unknown browser tyep?
  5. What’s the probability that it’s an attack given that it uses an unknown browser type and has tried to login more than 5 times?
# To do

2. Conditional Random Variables

Let us use the following notation:

  • \(X:\) ‘A traffic is an attack’ (1: attack, 0: not an attack)
  • \(Y:\) ‘The number of login attempts’
  • \(Z:\) ‘The number of failed logins’

A. What’s the distribution of \(X\)?

B. Visualize the distribution of \(Y\). Which distribution do you think best describes the distribution of \(Y\)? Give its PMF.

C. Repeat the previous question with \(Z\).

D. If we let \(W = (X\mid Y\geq 5)\) be the random variable that represents the probability of an attack given that there are at least 5 login attempts, what’s its distribution?

E. If we let \(V = (Z\mid X=0)\) be the random variable that represents the number of failed logins given that it’s not an attack, what’s its distribution?

# To do