Threat Hunting System for Protecting Critical Infrastructures Using a Machine Learning Approach

被引:2
|
作者
Lozano, Mario Aragones [1 ]
Llopis, Israel Perez [1 ]
Domingo, Manuel Esteve [1 ]
机构
[1] Univ Politecn Valencia, Commun Dept, Valencia 46022, Spain
关键词
critical infrastructure protection; threat hunting; cyberattacks; artificial intelligence; machine learning; INTELLIGENCE;
D O I
10.3390/math11163448
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
Cyberattacks are increasing in number and diversity in nature daily, and the tendency for them is to escalate dramatically in the forseeable future, with critical infrastructures (CI) assets and networks not being an exception to this trend. As time goes by, cyberattacks are more complex than before and unknown until they spawn, being very difficult to detect and remediate. To be reactive against those cyberattacks, usually defined as zero-day attacks, cyber-security specialists known as threat hunters must be in organizations' security departments. All the data generated by the organization's users must be processed by those threat hunters (which are mainly benign and repetitive and follow predictable patterns) in short periods to detect unusual behaviors. The application of artificial intelligence, specifically machine learning (ML) techniques (for instance NLP, C-RNN-GAN, or GNN), can remarkably impact the real-time analysis of those data and help to discriminate between harmless data and malicious data, but not every technique is helpful in every circumstance; as a consequence, those specialists must know which techniques fit the best at every specific moment. The main goal of the present work is to design a distributed and scalable system for threat hunting based on ML, and with a special focus on critical infrastructure needs and characteristics.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] Threat Hunting Architecture Using a Machine Learning Approach for Critical Infrastructures Protection
    Lozano, Mario Aragones
    Llopis, Israel Perez
    Domingo, Manuel Esteve
    BIG DATA AND COGNITIVE COMPUTING, 2023, 7 (02)
  • [2] A Machine Learning-Driven Threat Hunting Architecture for Protecting Critical Infrastructures
    Lozano, Mario Aragones
    Llopis, Israel Perez
    Alarcon, Alfonso Climente
    Domingo, Manuel Esteve
    2023 19TH INTERNATIONAL CONFERENCE ON THE DESIGN OF RELIABLE COMMUNICATION NETWORKS, DRCN, 2023,
  • [3] TRUSTY: A Solution for Threat Hunting Using Data Analysis in Critical Infrastructures
    Radoglou-Grammatikis, Panagiotis
    Liatifis, Athanasios
    Grigoriou, Elisavet
    Saoulidis, Theocharis
    Sarigiannidis, Antonios
    Lagkas, Thomas
    Sarigiannidis, Panagiotis
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 485 - 490
  • [4] A Machine Learning Approach to Threat Hunting in Malicious PDF Files
    Teymourlouei, Haydar
    Harris, Vareva E.
    2023 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE, CSCI 2023, 2023, : 782 - 787
  • [5] Detecting Advanced Persistent Threat Malware Using Machine Learning-Based Threat Hunting
    Lin, Tien-Chih
    Guo, Cheng-Chung
    Yang, Chu -Sing
    PROCEEDINGS OF THE 18TH EUROPEAN CONFERENCE ON CYBER WARFARE AND SECURITY (ECCWS 2019), 2019, : 760 - 768
  • [6] Building Machine Learning-based Threat Hunting System from Scratch
    Chen, Chung-Kuan
    Lin, Si-Chen
    Huang, Szu-Chun
    Chu, Yung-Tien
    Lei, Chin-Laung
    Huang, Chun-Ying
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2022, 3 (03):
  • [7] A system design for surveillance systems protecting critical infrastructures
    Jungert, Erland
    Hallberg, Niklas
    Wadstromer, Niclas
    JOURNAL OF VISUAL LANGUAGES AND COMPUTING, 2014, 25 (06): : 650 - 657
  • [8] Proactive Threat Hunting in Critical Infrastructure Protection through Hybrid Machine Learning Algorithm Application
    Shan, Ali
    Myeong, Seunghwan
    SENSORS, 2024, 24 (15)
  • [9] Insider Threat Detection Using Machine Learning Approach
    Sarhan, Bushra Bin
    Altwaijry, Najwa
    APPLIED SCIENCES-BASEL, 2023, 13 (01):
  • [10] Minitrack Introduction Machine Learning and AI: Cybersecurity and Threat Hunting
    Kayhan, Varol O.
    Shivendu, Shivendu
    Agrawal, Manish
    Zeng, David
    Proceedings of the Annual Hawaii International Conference on System Sciences, 2024,