谷歌浏览器插件
订阅小程序
在清言上使用

A Data Mining Based System for Automating Creation of Cyber Threat Intelligence.

9TH INTERNATIONAL SYMPOSIUM ON DIGITAL FORENSICS AND SECURITY (ISDFS'21)(2021)

引用 1|浏览1
暂无评分
摘要
In this study, since it is a laborious task to create cyber threat intelligence (CTI), a system that will facilitate the generating of CTI with data mining techniques is proposed. With the system, live or saved traffic records can be classified according to the learned attack types, and CTI can be generated automatically in a standard format. The system is able to update the training set with new attack types by allowing unknown attacks to be identified by expert opinion. The proposed system was designed by a literature survey. Modules of the system have been developed in line with the design, and knowledge discovery in databases processes, including algorithms, have been implemented. In order to verify the achievements of the system, it has been shown that the results of the studies in the literature and the accuracy obtained through the Weka tool, which has proven its reliability in data mining, are similar to the results of the proposed system. Then, the up-to-dateness of the attack types in the preferred dataset was analyzed. As a case study for the application of the proposed system, the traffic was recorded by drawing the attention of the attackers with honeypot systems on a server exposed to the internet for 24 hours, and CTI was generated through these records. It has been shown that the proposed system can be easily used to successfully generate CTI.
更多
查看译文
关键词
data mining,intrusion detection system,cyber threat intelligence
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要