Characterizing and Leveraging Granger Causality in Cybersecurity: Framework and Case Study

Characterizing and Leveraging Granger Causality in Cybersecurity: Framework and Case Study
复制标题

DOI:
10.4108/eai.11-5-2021.169912
复制
发表时间:
2021-06
期刊:
EAI Endorsed Trans. Security Safety
影响因子:
--
通讯作者:
Van Trieu-Do;Richard B. Garcia-Lebron;Maochao Xu;Shouhuai Xu;Yusheng Feng
Van Trieu-Do;Richard B. Garcia-Lebron;Maochao Xu;Shouhuai Xu;Yusheng Feng
中科院分区:
其他
文献类型:
--
作者:
Van Trieu-Do;Richard B. Garcia-Lebron;Maochao Xu;Shouhuai Xu;Yusheng Feng

文献摘要

相似文献

因果关系是一个有趣的概念,一旦驯服,可以有许多应用。虽然在其他领域已得到广泛研究,但其在网络安全领域的相关性和有用性却很少受到关注。在本文中,我们提出了一个系统的调查因果关系,称为格兰杰因果关系(G-因果关系),在网络安全的一个特定的方法。我们提出了一个框架,称为网络安全格兰杰因果关系(CGC),用于表征G-因果关系在网络攻击率时间序列中的存在,并利用G-因果关系来预测(即,预测)网络攻击率。该框架提出了一系列研究问题,可用于或适用于研究其他类型网络安全时间序列数据中的G-因果关系。为了证明CGC的有用性,我们提出了一个案例研究,将其应用到一个特定的网络攻击数据集收集在一个蜜罐。从这个案例研究中,我们得出了一些见解G-因果关系在网络安全领域的有用性和局限性。
Causality is an intriguing concept that once tamed, can have many applications. While having been widely investigated in other domains, its relevance and usefulness in the cybersecurity domain has received little attention. In this paper, we present a systematic investigation of a particular approach to causality, known as Granger causality (G-causality), in cybersecurity. We propose a framework, dubbed Cybersecurity Granger Causality (CGC), for characterizing the presence of G-causality in cyber attack rate time series and for leveraging G-causality to predict (i.e., forecast) cyber attack rates. The framework o ff ers a range of research questions, which can be adopted or adapted to study G-causality in other kinds of cybersecurity time series data. In order to demonstrate the usefulness of CGC, we present a case study by applying it to a particular cyber attack dataset collected at a honeypot. From this case study, we draw a number of insights into the usefulness and limitations of G-causality in the cybersecurity domain.