Statistical Cybersecurity: A Brief Discussion of Challenges, Data Structures, and Future Directions
Statistical Cybersecurity: A Brief Discussion of Challenges, Data Structures, and Future Directions
复制标题
统计网络安全:挑战、数据结构和未来方向的简要讨论
DOI:
10.1162/99608f92.240383c7
复制
发表时间:
2023
期刊:
影响因子:
--
通讯作者:
Sanna Passino F
中科院分区:
文献类型:
--
作者:
Sanna Passino F
We congratulate the authors of Hero et al.(2023) for a very interesting and comprehensive review of the current challenges in the field of statistics and data science for cybersecurity applications. In this commentary, we would like to contribute by expanding upon some of the points raised by the authors in their Section 3,“Data-Driven Cybersecurity for Enterprise Systems,” describing some of the challenges faced by statisticians working in cybersecurity, in particular regarding data structures, and emphasising directions for future work and research in statistical modeling for cybersecurity.As Hero et al.(2023) point out, statistical modeling currently represents the main tool for anomaly-based detection, which looks for deviations from a model of the normal behavior of the network (see, for example, Chandola et al., 2009). As discussed in the article, statistical models have the main advantage of being able to assign anomaly scores to previously unseen events, by borrowing strength between different users, hosts, and processes. In this way, previously unobserved attacks, or zero-day exploits, can still potentially be identified. This remarkable feature of statistical models has been demonstrated extensively in the literature, with the objective, for example, to discover compromised credentials and lateral movement within a computer network (Neil et al., 2013).