计算机科学
计算机安全
鉴定(生物学)
对抗性机器学习
假阳性悖论
对抗制
工业控制系统
控制(管理)
人工智能
机器学习
植物
生物
作者
Muhammad Imran,Hafeez Ur Rehman Siddiqui,Ali Raza,Muhammad Amjad Raza,Furqan Rustam,Imran Ashraf
标识
DOI:10.1016/j.cose.2023.103445
摘要
Cybersecurity incident response is a very crucial part of the cybersecurity management system. Adversaries emerge and evolve with new cybersecurity tactics, techniques, and procedures (TTPs). It is essential to detect the TTPs in a timely manner to respond effectively and mitigate the vulnerabilities to secure business operations. This research focuses on TTP identification and detection based on a machine learning approach. Early identification and detection are paramount in protecting, responding to, and recovering from such adversarial attacks. Analyzing use cases is a critical tool to ensure proper and in-depth evaluation of sector-specific cybersecurity challenges. In this regard, this study investigates existing known methodologies for cyber-attacks such as Mitre attacks, and developed a method for identifying threat cases. In addition, Windows-based threat cases are implemented, comprehensive datasets are generated, and supervised machine learning models are applied to detect threats effectively and efficiently. Random forest outperforms other models with the highest accuracy of 99%. Future work can be done for generating threat cases based on multiple log sources, including network security and endpoint protection device, and achieve high accuracy by removing false positives using machine learning. Similarly, real-time threat detection is also envisioned for future work.
科研通智能强力驱动
Strongly Powered by AbleSci AI