首页> 外文会议>Annual IEEE International Carnahan Conference on Security Technology >Cyber security risk assessment using an interpretable evolutionary fuzzy scoring system
【24h】

Cyber security risk assessment using an interpretable evolutionary fuzzy scoring system

机译:网络安全风险评估使用可解释的进化模糊分量系统

获取原文

摘要

An efficient and effective security risk assessment benefits a lot on realizing the potential threats changing, uncovering emergency when maintaining cyber security, and maximize utilization of available resource. However, traditional cyber security risk assessments are usually based on knowledge-driven approach which is suffered from demanding lots of proper domain knowledge and time-consuming human interaction to generate assessment model. In this research, aiming to alleviate the efforts taken by domain experts, we propose a novel interpretable evolutionary fuzzy scoring system, which is innovated in data-driven way, for cyber security risk assessing. The design process of the proposed method is elaborately optimized according to three objectives: accurate, compact, and most important, interpretable. Performance of proposed method is evaluated by both well-known machine learning benchmarks and real cyber security risk assessment dataset. Experimental results deliver insights as followings: 1) The delivered real-valued scoring can successfully quantify the degree of cyber security risk, just like the conventional knowledge-driven methods do. 2) The proposed scoring system can be further modified as a wrapper method to making alert, when given system-suggested or human-specified value as cyber risk alert threshold in advance. 3) The derived scoring system with a compact fuzzy rule base can generate interpretable result that depicts clear data distribution to users.
机译:有效且有效的安全风险评估在实现维持网络安全时揭示紧急情况的潜在威胁,并最大限度地利用可用资源的安全性,有效的安全风险评估受益匪浅。然而,传统的网络安全风险评估通常基于知识驱动的方法,这些方法遭受要求许多适当的域名知识和耗时的人类相互作用来产生评估模型。在这项研究中,旨在缓解领域专家所采取的努力,提出了一种新颖的可解释的进化模糊评分系统,以数据驱动方式创新,用于网络安全风险评估。该方法的设计过程根据三个目标进行精细优化:准确,紧凑,最重要的,可解释。所提出的方法的性能由着名的机器学习基准和真正的网络安全风险评估数据集评估。实验结果如下所示的洞察力:1)交付的实价评分可以成功量化网络安全风险,就像传统的知​​识驱动的方法一样。 2)当给定系统建议或人类指定的价值作为网络风险警报阈值时,可以进一步修改作为提出警报的包装方法。 3)具有紧凑模糊规则库的导出评分系统可以生成可解释的结果,其描绘了对用户的清晰数据分发。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号