Intelligent Algorithms for Event Processing and Decision Making on Information Protection Strategies against Cyberattacks

Author:

Asyaev Grigorii1,Sokolov Alexander1,Ruchay Alexey12ORCID

Affiliation:

1. Department of Information Security, South Ural State University, Chelyabinsk 454080, Russia

2. Department of Mathematics, Chelyabinsk State University, Chelyabinsk 454001, Russia

Abstract

This paper considers the main approaches to building algorithms for the decision support systems of information protection strategies against cyberattacks in the networks of automated process control systems (the so-called recommender systems). The advantages and disadvantages of each of the considered algorithms are revealed, and their applicability to the processing of the information security events of the UNSW-NB 15 dataset is analyzed. The dataset used contains raw network packets collected using the IXIA PerfectStorm software in the CyberRange laboratory of the Australian Cyber Security Centre (Canberra) in order to create a hybrid of the simulation of the real actions and the synthetic behavior of the network traffic generated during attacks. The possibility of applying four semantic proximity algorithms to partition process the data into clusters based on attack type in a distribution control system (DCS) is analyzed. The percentage of homogeneous records belonging to a particular type of attack is used as the metric that determines the optimal method of cluster partitioning. This metric was chosen under the assumption that cyberattacks located “closer” to each other in the multidimensional space have similar defense strategies. A hypothesis is formulated about the possibility of transferring knowledge about attacks from the vector feature space into a semantic form using semantic proximity methods. The percentage of homogeneous entries was maximal when the cosine proximity measure was used, which confirmed the hypothesis about the possibility of applying the corresponding algorithm in the recommender system.

Funder

Russian Science Foundation

Publisher

MDPI AG

Subject

General Mathematics,Engineering (miscellaneous),Computer Science (miscellaneous)

Reference39 articles.

1. Griffiths, C. (2023, June 11). The Latest 2023 Cyber Crime Statistics. Available online: https://aag-it.com/the-latest-cyber-crime-statistics/.

2. Frąckiewiczin, M. (2023, June 11). The Role of Artificial Intelligence in Cybersecurity Threat Detection, Artificial Intelligence, TS2 Spaceon. 18 June 2023. Available online: https://ts2.space/en/the-role-of-artificial-intelligence-in-cybersecurity-threat-detection/.

3. Bolshev, A.K. (2011). Algorithms of Traffic Transformation and Classification for Intrusion Detection in Computer Networks, Saint-Petersburg State Electrotechnical University (SPbGETU). Abstracts of V.I. Ulyanov (Lenin) LETI.

4. Vitenburg, E.A. Formalized model of intellectual decision support system in the field of information protection. Proceedings of TulSU. Technical Sciences. 2017. No. 7.

5. Abdullahi, M., Baashar, Y., Alhussian, H., Alwadain, A., Aziz, N., Capretz, L.F., and Abdulkadir, S.J. (2022). Detecting Cybersecurity Attacks in Internet of Things Using Artificial Intelligence Methods: A Systematic Literature Review. Electronics, 11.

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3