期刊论文详细信息
Cybersecurity
Forecasting cyberattacks with incomplete, imbalanced, and insignificant data
Ahmet Okutan2  Gordon Werner2  Shanchieh Jay Yang2  Katie McConky3 
[1]Systems Engineering, Rochester Institute of Technology, Rochester, USA
[2]Computer Engineering, Rochester Institute of Technology, Rochester, USA
[3]Industrial &
关键词: Cyber security;    Forecasting;    Unconventional signals;   
DOI  :  10.1186/s42400-018-0016-5
学科分类:计算机科学(综合)
来源: Springer
PDF
【 摘 要 】
Having the ability to forecast cyberattacks before they happen will unquestionably change the landscape of cyber warfare and cyber crime. This work predicts specific types of attacks on a potential victim network before the actual malicious actions take place. The challenge to forecasting cyberattacks is to extract relevant and reliable signals to treat sporadic and seemingly random acts of adversaries. This paper builds on multi-faceted machine learning solutions and develops an integrated system to transform large volumes of public data to aggregate signals with imputation that are relevant and predictive of cyber incidents. A comprehensive analysis of the individual parts and the integrated whole demonstrates the effectiveness and trade-offs of the proposed approach. Using 16-months of reported cyber incidents by an anonymized victim organization, the integrated approach achieves up to 87%, 90%, and 96% AUC for forecasting endpoint-malware, malicious-destination, and malicious-email attacks, respectively. When assessed month-by-month, the proposed approach shows robustness to perform consistently well, achieving F-Measure between 0.6 and 1.0. The framework also enables an examination of which unconventional signals are meaningful for cyberattack forecasting.
【 授权许可】

CC BY   

【 预 览 】
附件列表
Files Size Format View
RO201904024399966ZK.pdf 1775KB PDF download
  文献评价指标  
  下载次数:13次 浏览次数:15次