Threat Hunting System for Protecting Critical Infrastructures Using a Machine Learning Approach

被引:2
|
作者
Lozano, Mario Aragones [1 ]
Llopis, Israel Perez [1 ]
Domingo, Manuel Esteve [1 ]
机构
[1] Univ Politecn Valencia, Commun Dept, Valencia 46022, Spain
关键词
critical infrastructure protection; threat hunting; cyberattacks; artificial intelligence; machine learning; INTELLIGENCE;
D O I
10.3390/math11163448
中图分类号
O1 [数学];
学科分类号
0701 ; 070101 ;
摘要
Cyberattacks are increasing in number and diversity in nature daily, and the tendency for them is to escalate dramatically in the forseeable future, with critical infrastructures (CI) assets and networks not being an exception to this trend. As time goes by, cyberattacks are more complex than before and unknown until they spawn, being very difficult to detect and remediate. To be reactive against those cyberattacks, usually defined as zero-day attacks, cyber-security specialists known as threat hunters must be in organizations' security departments. All the data generated by the organization's users must be processed by those threat hunters (which are mainly benign and repetitive and follow predictable patterns) in short periods to detect unusual behaviors. The application of artificial intelligence, specifically machine learning (ML) techniques (for instance NLP, C-RNN-GAN, or GNN), can remarkably impact the real-time analysis of those data and help to discriminate between harmless data and malicious data, but not every technique is helpful in every circumstance; as a consequence, those specialists must know which techniques fit the best at every specific moment. The main goal of the present work is to design a distributed and scalable system for threat hunting based on ML, and with a special focus on critical infrastructure needs and characteristics.
引用
收藏
页数:18
相关论文
共 50 条
  • [31] A Machine-Learning Approach for the Prediction of Internal Corrosion in Pipeline Infrastructures
    Canonaco, Giuseppe
    Roveri, Manuel
    Alippi, Cesare
    Podenzani, Fabrizio
    Bennardo, Antonio
    Conti, Marco
    Mancini, Nicola
    2021 IEEE INTERNATIONAL INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE (I2MTC 2021), 2021,
  • [32] Automating threat modeling using an ontology framework: Validated with data from critical infrastructures
    Valja, Margus
    Heiding, Fredrik
    Franke, Ulrik
    Lagerstrom, Robert
    CYBERSECURITY, 2020, 3 (01)
  • [33] AN IN-MOLD MONITORING AND PROTECTING SYSTEM OF THE INJECTION MOLDING MACHINE USING OFFSET CORRECTION AND DYNAMIC SAFE RANGE LEARNING APPROACH
    Chi, Ting-Yun
    Xin, Men-Chang
    Huang, Chun-Yen
    2015 FIRST INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE THEORY, SYSTEMS AND APPLICATIONS (CCITSA 2015), 2015, : 64 - 68
  • [34] Malware Cyber Threat Intelligence System for Internet of Things (IoT) Using Machine Learning
    Xiao P.
    Journal of Cyber Security and Mobility, 2024, 13 (01): : 53 - 90
  • [35] Enhanced Cyber Threat Detection System Leveraging Machine Learning Using Data Augmentation
    Iftikhar, Umar
    Ali, Syed Abbas
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2025, 16 (02) : 218 - 225
  • [36] Machine Learning for Threat Recognition in Critical Cyber-Physical Systems
    Perrone, Paola
    Flammini, Francesco
    Setola, Roberto
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 298 - 303
  • [37] Cyber Threat Intelligence for IoT Using Machine Learning
    Mishra, Shailendra
    Albarakati, Aiman
    Sharma, Sunil Kumar
    PROCESSES, 2022, 10 (12)
  • [38] A Machine Learning Approach to Detection of Critical Alerts from Imbalanced Multi-Appliance Threat Alert Logs
    Ndichu, Samuel
    Ban, Tao
    Takahashi, Takeshi
    Inoue, Daisuke
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 2119 - 2127
  • [39] Intrusion Detection System Using Machine Learning Approach: A Review
    Sharma, Kapil
    Chawla, Meenu
    Tiwari, Namita
    INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING AND COMMUNICATIONS, ICICC 2022, VOL 1, 2023, 473 : 727 - 734
  • [40] EFFICIENT DIAGNOSTIC CARDIAC SYSTEM USING MACHINE LEARNING APPROACH
    Qureshi, Mujtaba Ashraf
    Shrivastava, Azad Kumar
    INTERNATIONAL TRANSACTION JOURNAL OF ENGINEERING MANAGEMENT & APPLIED SCIENCES & TECHNOLOGIES, 2020, 11 (15):