妥协
杠杆(统计)
恶意软件
计算机科学
跟踪(心理语言学)
计算机安全
假阳性悖论
散列函数
机器学习
社会科学
语言学
哲学
社会学
作者
Breno Tostes,Leonardo Ventura,Enrico Lovat,Matheus Martins,Daniel Sadoc Menasché
出处
期刊:Cornell University - arXiv
日期:2023-01-01
标识
DOI:10.48550/arxiv.2307.16852
摘要
Indicators of Compromise (IOCs), such as IP addresses, file hashes, and domain names associated with known malware or attacks, are cornerstones of cybersecurity, serving to identify malicious activity on a network. In this work, we leverage real data to compare different parameterizations of IOC aging models. Our dataset comprises traffic at a real environment for more than 1 year. Among our trace-driven findings, we determine thresholds for the ratio between miss over monitoring costs such that the system benefits from storing IOCs for a finite time-to-live (TTL) before eviction. To the best of our knowledge, this is the first real world evaluation of thresholds related to IOC aging, paving the way towards realistic IOC decaying models.
科研通智能强力驱动
Strongly Powered by AbleSci AI