vix.ing · top · new · best · stats · spec

NERD: Neural Network for Edict of Risky Data Streams

2020/07/08 by Sandro Passarelli, Gundogan Cem, Passarelli, Sandro +7
Computer Science · #Anomaly Detection Techniques and Applications #Computers and Society (cs.CY) #Cryptography and Security (cs.CR) #Data Stream Mining Techniques #Distributed #FOS: Computer and information sciences #Information Retrieval (cs.IR) #Network Security and Intrusion Detection #Networking and Internet Architecture (cs.NI) #Parallel #and Cluster Computing (cs.DC)

paper · pdf · doi:10.48550/arxiv.2007.07753

openalex publication_date 2020/07/08 · openalex created_date 2020/07/16 · openalex updated_date 2026/07/28

Abstract

Cyber incidents can have a wide range of cause from a simple connection loss to an insistent attack. Once a potential cyber security incidents and system failures have been identified, deciding how to proceed is often complex. Especially, if the real cause is not directly in detail determinable. Therefore, we developed the concept of a Cyber Incident Handling Support System. The developed system is enriched with information by multiple sources such as intrusion detection systems and monitoring tools. It uses over twenty key attributes like sync-package ratio to identify potential security incidents and to classify the data into different priority categories. Afterwards, the system uses artificial intelligence to support the further decision-making process and to generate corresponding reports to brief the Board of Directors. Originating from this information, appropriate and detailed suggestions are made regarding the causes and troubleshooting measures. Feedback from users regarding the problem solutions are included into future decision-making by using labelled flow data as input for the learning process. The prototype shows that the decision making can be sustainably improved and the Cyber Incident Handling process becomes much more effective.

Related