Statistical Cybersecurity: A Brief Discussion of Challenges, Data Structures, and Future Directions

Statistical Cybersecurity: A Brief Discussion of Challenges, Data Structures, and Future Directions
复制标题

统计网络安全:挑战、数据结构和未来方向的简要讨论

DOI:
10.1162/99608f92.240383c7
复制
发表时间:
2023
期刊:
Harvard Data Science Review
影响因子:
--
通讯作者:
Sanna Passino F
Sanna Passino F
中科院分区:
--
文献类型:
--
作者:
Sanna Passino F

文献摘要

相似文献

我们祝贺Hero等人的作者。(2023)对网络安全应用统计和数据科学领域当前面临的挑战进行了非常有趣和全面的审查。在这篇评论中,我们希望通过扩展作者在第3节“企业系统的数据驱动的网络安全”中提出的一些观点来做出贡献,描述在网络安全中工作的统计学家所面临的一些挑战,特别是关于数据结构,并强调网络安全统计建模未来工作和研究的方向。(2023)指出,统计建模目前代表了基于异常的检测的主要工具,其寻找与网络的正常行为的模型的偏差(例如,参见Albertola等人,2009年)。正如本文所讨论的,统计模型的主要优点是能够通过借用不同用户、主机和进程之间的力量,为以前看不见的事件分配异常分数。通过这种方式,仍然可以识别以前未观察到的攻击或零日漏洞。统计模型的这一显著特征已经在文献中被广泛地证明,其目的例如是发现计算机网络内的受损凭证和横向移动(Neil等人,2013年)。
We congratulate the authors of Hero et al.(2023) for a very interesting and comprehensive review of the current challenges in the field of statistics and data science for cybersecurity applications. In this commentary, we would like to contribute by expanding upon some of the points raised by the authors in their Section 3,“Data-Driven Cybersecurity for Enterprise Systems,” describing some of the challenges faced by statisticians working in cybersecurity, in particular regarding data structures, and emphasising directions for future work and research in statistical modeling for cybersecurity.As Hero et al.(2023) point out, statistical modeling currently represents the main tool for anomaly-based detection, which looks for deviations from a model of the normal behavior of the network (see, for example, Chandola et al., 2009). As discussed in the article, statistical models have the main advantage of being able to assign anomaly scores to previously unseen events, by borrowing strength between different users, hosts, and processes. In this way, previously unobserved attacks, or zero-day exploits, can still potentially be identified. This remarkable feature of statistical models has been demonstrated extensively in the literature, with the objective, for example, to discover compromised credentials and lateral movement within a computer network (Neil et al., 2013).