首页> 外文期刊>Quality Control, Transactions >From logs to Stories: Human-Centred Data Mining for Cyber Threat Intelligence
【24h】

From logs to Stories: Human-Centred Data Mining for Cyber Threat Intelligence

机译:从日志到故事:人以网络威胁情报为中心的数据挖掘

获取原文
获取原文并翻译 | 示例
       

摘要

An average medium-sized organisation logs approx. 10 to 500 mln events per day on the system. Only less than 5% of threat alerts are being investigated by the specialised staff, leaving the security hole open for potential attacks. Insufficient information in alert message produced in machine-friendly rather than human-friendly format causes cognitive overload on currently limited cybersecurity resources. In this paper, the model that generates the report in natural language by means of applying novel storytelling techniques from security logs is proposed. The solution caters for different levels of reader expertise and preference by providing adjustable templates, filled from both local and global knowledge base. The validation is performed on case study from Security Operations Centre (SOC) at educational institution. The report generated proves superior to existing approach in terms of comprehension (increased cognition) and completeness (enriched context). The evaluation demonstrates power of storytelling in potential threats interpretation in cybersecurity context.
机译:平均中型组织的日志约为。系统上每天10至500万毫升。专业员工只调查了不到5%的威胁警报,让安全洞打开潜在攻击。在机器友好而不是人类友好格式生产的警报信息中的信息不足会导致当前有限的网络安全资源上的认知过载。在本文中,提出了通过从安全日志应用新的讲故事技术生成自然语言报告的模型。通过提供可调节的模板,解决方案可以提供不同级别的读者专业知识和偏好,从本地和全球知识库中填充。在教育机构安全运营中心(SoC)的案例研究中进行了验证。该报告在理解(认知)和完整性增加(丰富的上下文)方面,所产生的结果优于现有的方法。评价表明讲故事在网络安全环境中潜在威胁解释的权力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号