Threat Hunting Architecture Using a Machine Learning Approach for Critical Infrastructures Protection

نویسندگان

چکیده

The number and the diversity in nature of daily cyber-attacks have increased last few years, trends show that both will grow exponentially near future. Critical Infrastructures (CI) operators are not excluded from these issues; therefore, CIs’ Security Departments must their own group IT specialists to prevent respond cyber-attacks. To introduce more challenges existing cyber security landscape, many attacks unknown until they spawn, even a long time after initial actions, posing increasing difficulties on detection remediation. be reactive against those cyber-attacks, usually defined as zero-day attacks, organizations Threat Hunters at departments aware unusual behaviors Modus Operandi. face vast amounts data (mainly benign repetitive, following predictable patterns) short periods detect any anomaly, with associated cognitive overwhelming. application Artificial Intelligence, specifically Machine Learning (ML) techniques, can remarkably impact real-time analysis data. Not only that, but providing useful visualizations significantly increase Hunters’ understanding issues facing. Both help discriminate between harmless malicious data, alleviating analysts above-mentioned overload means enhance Cyber Situational Awareness (CSA). This work aims design system architecture helps Hunters, using approach applying state-of-the-art visualization techniques order protect based distributed, scalable online configurable framework interconnected modular components.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Cyber-Threat Intelligence Architecture for Smart-Grid Critical Infrastructures Protection

Critical infrastructures (CIs) are becoming increasingly sophisticated with embedded cyber-physical systems (CPSs) that provide managerial automation and autonomic controls. Yet these advances expose CI components to new cyber-threats, leading to a chain of dysfunctionalities with catastrophic socio-economical implications. We propose a comprehensive architectural model to support the developme...

متن کامل

Critical Infrastructures as Complex Systems: A Multi-level Protection Architecture

This paper describes a security platform as a complex system of holonic communities, that are hierarchically organized, but selfreconfigurable when some of them are detached or cannot otherwise operate. Furthermore, every possible subset of holons may work autonomously, while maintaining self-conscience of its own mission, action lines and goals. Each holonic unit, either elementary or composit...

متن کامل

Critical Infrastructures under Threat: Learning from the Anthrax Scare

Conventional thinking in emergency and crisis management focuses on the application of codified procedures to unforeseen contingencies. Modern society’s increased dependence on critical infrastructures and the emerging vulnerabilities of these large-scale networks create challenges that are hard to meet with conventional tools of crisis management. This article discusses the inherent vulnerabil...

متن کامل

Intrusion-Tolerant Protection for Critical Infrastructures

Today’s critical infrastructures like the Power Grid are essentially physical processes controlled by computers connected by networks. They are usually as vulnerable as any other interconnected computer system, but their failure has a high socio-economic impact. The paper describes a new construct for the protection of these infrastructures, based on distributed algorithms and mechanisms implem...

متن کامل

The CRUTIAL Architecture for Critical Information Infrastructures

In this chapter we discuss the susceptibility of critical information infrastructures to computer-borne attacks and faults, mainly due to their largely computerized nature, and to the pervasive interconnection of systems all over the world. We discuss how to overcome these problems and achieve resilience of critical information infrastructures, through adequate architectural constructs. The arc...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Big data and cognitive computing

سال: 2023

ISSN: ['2504-2289']

DOI: https://doi.org/10.3390/bdcc7020065