Predictive Cyber Situational Awareness and Personalized Blacklisting: A Sequential Rule Mining Approach

被引:17
|
作者
Husak, Martin [1 ]
Bajtos, Tomas [2 ]
Kaspar, Jaroslav [1 ]
Bou-Harb, Elias [3 ]
Celeda, Pavel [1 ]
机构
[1] Masaryk Univ, Inst Comp Sci, Brno, Czech Republic
[2] Pavol Jozef Safarik Univ Kosice, Inst Comp Sci, Kosice, Slovakia
[3] Univ Texas San Antonio, Cyber Ctr Secur & Analyt, San Antonio, TX USA
基金
美国国家科学基金会;
关键词
Data mining; situational awareness; intrusion detection; attack prediction; INTRUSION DETECTION; EVENT;
D O I
10.1145/3386250
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Cybersecurity adopts data mining for its ability to extract concealed and indistinct patterns in the data, such as for the needs of alert correlation. Inferring common attack patterns and rules from the alerts helps in understanding the threat landscape for the defenders and allows for the realization of cyber situational awareness, including the projection of ongoing attacks. In this article, we explore the use of data mining, namely sequential rule mining, in the analysis of intrusion detection alerts. We employed a dataset of 12 million alerts from 34 intrusion detection systems in 3 organizations gathered in an alert sharing platform, and processed it using our analytical framework. We execute the mining of sequential rules that we use to predict security events, which we utilize to create a predictive blacklist. Thus, the recipients of the data from the sharing platform will receive only a small number of alerts of events that are likely to occur instead of a large number of alerts of past events. The predictive blacklist has the size of only 3% of the raw data, and more than 60% of its entries are shown to be successful in performing accurate predictions in operational, real-world settings.
引用
收藏
页数:16
相关论文
共 15 条
  • [1] Improving Cyber Situational Awareness Through Data Mining and Predictive Analytic Techniques
    Pournouri, Sina
    Akhgar, Babak
    [J]. GLOBAL SECURITY, SAFETY AND SUSTAINABILITY: TOMORROW'S CHALLENGES OF CYBER SECURITY, ICGS3 2015, 2015, 534 : 21 - 34
  • [2] A Viable Systems Approach Towards Cyber Situational Awareness
    Craig, Richard
    Tryfonas, Theo
    May, John
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN AND CYBERNETICS (SMC), 2014, : 1405 - 1411
  • [3] A Novel Approach to Cyber Situational Awareness in Embedded Systems
    Denney, Kyle
    Lychev, Robert
    Kava, Donato
    Lee, Alice
    Vai, Michael
    Evancich, Nick
    Clark, Richard
    Lide, David
    Kwak, K. J.
    Li, Jason
    Lynch, Michael
    Tillotson, Kyle
    Tirenin, Walt
    Schafer, Doug
    [J]. 2021 IEEE HIGH PERFORMANCE EXTREME COMPUTING CONFERENCE (HPEC), 2021,
  • [4] On the Sequential Pattern and Rule Mining in the Analysis of Cyber Security Alerts
    Husak, Martin
    Kaspar, Jaroslav
    Bou-Harb, Elias
    Celeda, Pavel
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
  • [5] A Markov game theoretic data fusion approach for cyber Situational awareness
    Shen, Dan
    Chen, Genshe
    Cruz, Jose B., Jr.
    Haynes, Leonard
    Kruger, Martin
    Blasch, Erik
    [J]. MULTISENSOR, MULTISOURCE INFORMATION FUSION: ARCHITECTURES, ALGORITHMS, AND APPLICATIONS 2007, 2007, 6571
  • [6] Gamification as a neuroergonomic approach to improving interpersonal situational awareness in cyber defense
    Ask, Torvald F.
    Knox, Benjamin J.
    Lugo, Ricardo G.
    Hoffmann, Lukas
    Suetterlin, Stefan
    [J]. FRONTIERS IN EDUCATION, 2023, 8
  • [7] An Alternative Timing and Synchronization Approach for Situational Awareness and Predictive Analytics
    Chinthavali, Supriya
    Hasan, S. M. Shamimul
    Yoginath, Srikanth
    Xu, Haowen
    Nugent, Phil
    Jones, Terry
    Engebretsen, Cozmo
    Olatt, Joseph
    Tansakul, Varisara
    Christopher, Carter
    Polsky, Yarom
    [J]. 2022 IEEE 23RD INTERNATIONAL CONFERENCE ON INFORMATION REUSE AND INTEGRATION FOR DATA SCIENCE (IRI 2022), 2022, : 172 - 177
  • [8] A System for Predictive Data Analytics Using Sequential Rule Mining
    Sagare, Sandipkumar Chandrakant
    Shirgave, Suresh Kallu
    Kodavade, Dattatraya Vishnu
    [J]. INTERNATIONAL JOURNAL OF SOFTWARE INNOVATION, 2020, 8 (04) : 96 - 112
  • [9] Generating Real Time Cyber Situational Awareness Information Through Social Media Data Mining
    Rodriguez, Ariel
    Okamura, Koji
    [J]. 2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 2, 2019, : 502 - 507
  • [10] A Multi-Disciplinary Approach to High Level Fusion in Predictive Situational Awareness
    Costa, Paulo Cesar G.
    Chang, Kuo-Chu
    Laskey, Kathryn B.
    Carvalho, Rommel N.
    [J]. FUSION: 2009 12TH INTERNATIONAL CONFERENCE ON INFORMATION FUSION, VOLS 1-4, 2009, : 248 - 255