Challenges in Forecasting Malicious Events from Incomplete Data

04/06/2020
by   Nazgol Tavabi, et al.
7

The ability to accurately predict cyber-attacks would enable organizations to mitigate their growing threat and avert the financial losses and disruptions they cause. But how predictable are cyber-attacks? Researchers have attempted to combine external data – ranging from vulnerability disclosures to discussions on Twitter and the darkweb – with machine learning algorithms to learn indicators of impending cyber-attacks. However, successful cyber-attacks represent a tiny fraction of all attempted attacks: the vast majority are stopped, or filtered by the security appliances deployed at the target. As we show in this paper, the process of filtering reduces the predictability of cyber-attacks. The small number of attacks that do penetrate the target's defenses follow a different generative process compared to the whole data which is much harder to learn for predictive models. This could be caused by the fact that the resulting time series also depends on the filtering process in addition to all the different factors that the original time series depended on. We empirically quantify the loss of predictability due to filtering using real-world data from two organizations. Our work identifies the limits to forecasting cyber-attacks from highly filtered data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/14/2018

Predicting Cyber Events by Leveraging Hacker Sentiment

Recent high-profile cyber attacks exemplify why organizations need bette...
research
10/30/2018

DARKMENTION: A Deployed System to Predict Enterprise-Targeted External Cyberattacks

Recent incidents of data breaches call for organizations to proactively ...
research
06/08/2018

Discovering Signals from Web Sources to Predict Cyber Attacks

Cyber attacks are growing in frequency and severity. Over the past year ...
research
03/26/2018

Forecasting Cyber Attacks with Imbalanced Data Sets and Different Time Granularities

If cyber incidents are predicted a reasonable amount of time before they...
research
09/24/2019

Mining user interaction patterns in the darkweb to predict enterprise cyber incidents

With rise in security breaches over the past few years, there has been a...
research
07/18/2019

An AI-based, Multi-stage detection system of banking botnets

Banking Trojans, botnets are primary drivers of financially-motivated cy...
research
04/23/2021

Leveraging Sharing Communities to Achieve Federated Learning for Cybersecurity

Automated cyber threat detection in computer networks is a major challen...

Please sign up or login with your details

Forgot password? Click here to reset