4.7 Article

Predictive methods in cyber defense: Current experience and research challenges

出版社

ELSEVIER
DOI: 10.1016/j.future.2020.10.006

关键词

Cybersecurity; Prediction; Forecasting; Data mining; Machine learning; Time series

资金

  1. ERDF CyberSecurity, Cyber-Crime and Critical Information Infrastructures Center of Excellence'' [CZ.02.1.01/0.0/0.0/16_019/0000822]
  2. Slovak Research and Development Agency [APVV-17-0568]
  3. European Union [833418]
  4. MEYS of the Czech Republic [CZ.02.1.01/0.0/0.0/16_013/0001797]
  5. ERDF

向作者/读者索取更多资源

This paper discusses predictive methods in cyber defense and evaluates three distinct approaches in a common environment. The methods, including data mining, dynamic network entity reputation scoring, and time series analysis, have shown promising accuracy and usability for predicting and projecting ongoing cyberattacks.
Predictive analysis allows next-generation cyber defense that is more proactive than current approaches based on intrusion detection. In this paper, we discuss various aspects of predictive methods in cyber defense and illustrate them on three examples of recent approaches. The first approach uses data mining to extract frequent attack scenarios and uses them to project ongoing cyberattacks. The second approach uses a dynamic network entity reputation score to predict malicious actors. The third approach uses time series analysis to forecast attack rates in the network. This paper presents a unique evaluation of the three distinct methods in a common environment of an intrusion detection alert sharing platform, which allows for a comparison of the approaches and illustrates the capabilities of predictive analysis for current and future research and cybersecurity operations. Our experiments show that all three methods achieved a sufficient technology readiness level for experimental deployment in an operational setting with promising accuracy and usability. Namely prediction and projection methods, despite their differences, are highly usable for predictive blacklisting, the first provides a more detailed output, and the second is more extensible. Network security situation forecasting is lightweight and displays very high accuracy, but does not provide details on predicted events. (C) 2020 Elsevier B.V. All rights reserved.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.7
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据