Network entity characterization and attack prediction

被引:27
|
作者
Bartos, Vaclav [1 ]
Zadnik, Martin [2 ]
Habib, Sheikh Mahbub [3 ]
Vasilomanolakis, Emmanouil [4 ]
机构
[1] CESNET, Prague, Czech Republic
[2] CESNET, Czech Natl Res & Educ Network, Prague, Czech Republic
[3] Continental AG, Secur & Privacy Competence Ctr SCC, Hannover, Germany
[4] Aalborg Univ, Ctr Commun Media & Informat Technol, Aalborg, Denmark
基金
欧盟地平线“2020”;
关键词
Network security; Alert sharing; Reputation database; Attack prediction; Alert prioritization; Machine learning;
D O I
10.1016/j.future.2019.03.016
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The devastating effects of cyber-attacks, highlight the need for novel attack detection and prevention techniques. Over the last years, considerable work has been done in the areas of attack detection as well as in collaborative defense. However, an analysis of the state of the art suggests that many challenges exist in prioritizing alert data and in studying the relation between a recently discovered attack and the probability of it occurring again. In this article, we propose a system that is intended for characterizing network entities and the likelihood that they will behave maliciously in the future. Our system, namely Network Entity Reputation Database System (NERDS), takes into account all the available information regarding a network entity (e. g. IP address) to calculate the probability that it will act maliciously. The latter part is achieved via the utilization of machine learning. Our experimental results show that it is indeed possible to precisely estimate the probability of future attacks from each entity using information about its previous malicious behavior and other characteristics. Ranking the entities by this probability has practical applications in alert prioritization, assembly of highly effective blacklists of a limited length and other use cases. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:674 / 686
页数:13
相关论文
共 50 条
  • [31] Knowledge Graph Entity Type Prediction with Relational Aggregation Graph Attention Network
    Zou, Changlong
    An, Jingmin
    Li, Guanyu
    SEMANTIC WEB, ESWC 2022, 2022, 13261 : 39 - 55
  • [32] Popularity Debiased Entity Linking by Adversarial Attack
    Guo, Congying
    Yan, Yang
    Wei, Qian
    PROCEEDINGS OF 2022 THE 6TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND SOFT COMPUTING, ICMLSC 20222, 2022, : 72 - 77
  • [33] Network Science of Teams: Characterization, Prediction, and Optimization
    Li, Liangyue
    Tong, Hanghang
    WSDM'18: PROCEEDINGS OF THE ELEVENTH ACM INTERNATIONAL CONFERENCE ON WEB SEARCH AND DATA MINING, 2018, : 783 - 784
  • [34] Lift coefficient prediction at high angle of attack using recurrent neural network
    Suresh, S
    Omkar, SN
    Mani, V
    Prakash, TNG
    AEROSPACE SCIENCE AND TECHNOLOGY, 2003, 7 (08) : 595 - 602
  • [35] Research on Key Technologies of Network Security Situational Awareness for Attack Tracking Prediction
    KOU Guang
    WANG Shuo
    TANG Guangming
    ChineseJournalofElectronics, 2019, 28 (01) : 162 - 171
  • [36] Optimizing BiLSTM Network Attack Prediction Based on Improved Gray Wolf Algorithm
    Qiu, Shaoming
    Wang, Yahui
    Lv, Yana
    Chen, Fen
    Zhao, Jiancheng
    APPLIED SCIENCES-BASEL, 2023, 13 (12):
  • [37] Research on Key Technologies of Network Security Situational Awareness for Attack Tracking Prediction
    Kou Guang
    Wang Shuo
    Tang Guangming
    CHINESE JOURNAL OF ELECTRONICS, 2019, 28 (01) : 162 - 171
  • [38] Entity Matters in News: An Association Network-Enhanced Method for News Reprint Prediction
    Li, Qiudan
    Liu, Hejing
    Yao, Riheng
    Xu, David Jingjun
    Zeng, Daniel D.
    IEEE INTELLIGENT SYSTEMS, 2022, 37 (01) : 99 - 107
  • [39] Design of Asthma Acute Attack Prediction System Based on Convolution Neural Network
    Sun, Z.
    INDIAN JOURNAL OF PHARMACEUTICAL SCIENCES, 2020, 82 : 63 - 63
  • [40] Heart Attack Prediction using Neural Network and Different Online Learning Methods
    Antar, Rayana Khaled
    ALotaibi, Shouq Talal
    AlGhamdi, Manal
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2021, 21 (06): : 77 - 88