Dynamic Scheduling of Cybersecurity Analysts for Minimizing Risk Using Reinforcement Learning

Dynamic Scheduling of Cybersecurity Analysts for Minimizing Risk Using Reinforcement Learning
复制标题

使用强化学习动态调度网络安全分析师以最小化风险

DOI:
--
复制
发表时间:
2016
影响因子:
5
通讯作者:
H. Çam
H. Çam
中科院分区:
计算机科学3区
文献类型:
--
作者:
R. Ganesan;S. Jajodia;Ankit Shah;H. Çam

文献摘要

被引文献

相似文献

网络防御机制的一个重要组成部分是其网络安全分析人员的足够人员配备水平,以及他们对传感器的最佳分配,以调查动态警报流量。当今数字系统所面临的不断增加的网络安全威胁需要一个强大的网络防御机制,该机制既能反应以减轻已知风险,又能主动准备处理未知风险。为了积极主动地处理未知的风险,上述劳动力必须动态地进行调度,以便系统能够适应对其劳动力(规模和专业知识组合)的日常随机需求。对劳动力的随机需求源于不同的警报生成及其重要性率,这导致网络安全分析师调度程序的不确定性,该调度程序试图安排分析师的工作并将传感器分配给分析师。传感器数据由自动处理系统进行分析,并生成警报。这些警报中的一部分被归类为重要警报,需要网络安全分析师进行彻底检查。在本文中,风险被定义为分析师没有彻底分析的重要警报的百分比。为了最大限度地降低风险,网络防御系统必须准确估计未来的重大警报生成率,并动态调度其工作人员,以满足随机的工作负载需求来分析它们。本文提出了一种基于强化学习的随机动态规划优化模型,该模型结合了上述对未来警报率的估计,并通过动态调度网络安全分析师来响应,以最大限度地降低风险(即,最大化分析师的重要警报覆盖范围),并将风险保持在预定的上限之下。本文测试了动态优化模型,并将结果与整数规划模型进行了比较,整数规划模型根据每日平均警报生成率优化静态人员配置需求,而不估计未来的警报率(静态劳动力模型)。结果表明,在有限的规划范围内,基于学习的优化模型,除了静态劳动力之外,还通过动态(随叫随到)劳动力,(a)能够比静态模型更好地平衡天数之间的风险并降低总体风险,(B)是可扩展的,能够识别组织中分析师专业知识的数量和正确组合,以及(c)能够确定它们的动态(随叫随到)调度和它们的传感器到分析员的分配,以便将风险保持在给定的上限以下。提出了几个元原则,这些原则来自优化模型,它们进一步作为招聘和安排网络安全分析师的指导原则。执行休息日计划,以确定满足网络安全系统劳动力约束和要求的分析师每周工作计划。
An important component of the cyber-defense mechanism is the adequate staffing levels of its cybersecurity analyst workforce and their optimal assignment to sensors for investigating the dynamic alert traffic. The ever-increasing cybersecurity threats faced by today’s digital systems require a strong cyber-defense mechanism that is both reactive in its response to mitigate the known risk and proactive in being prepared for handling the unknown risks. In order to be proactive for handling the unknown risks, the above workforce must be scheduled dynamically so the system is adaptive to meet the day-to-day stochastic demands on its workforce (both size and expertise mix). The stochastic demands on the workforce stem from the varying alert generation and their significance rate, which causes an uncertainty for the cybersecurity analyst scheduler that is attempting to schedule analysts for work and allocate sensors to analysts. Sensor data are analyzed by automatic processing systems, and alerts are generated. A portion of these alerts is categorized to be significant, which requires thorough examination by a cybersecurity analyst. Risk, in this article, is defined as the percentage of significant alerts that are not thoroughly analyzed by analysts. In order to minimize risk, it is imperative that the cyber-defense system accurately estimates the future significant alert generation rate and dynamically schedules its workforce to meet the stochastic workload demand to analyze them. The article presents a reinforcement learning-based stochastic dynamic programming optimization model that incorporates the above estimates of future alert rates and responds by dynamically scheduling cybersecurity analysts to minimize risk (i.e., maximize significant alert coverage by analysts) and maintain the risk under a pre-determined upper bound. The article tests the dynamic optimization model and compares the results to an integer programming model that optimizes the static staffing needs based on a daily-average alert generation rate with no estimation of future alert rates (static workforce model). Results indicate that over a finite planning horizon, the learning-based optimization model, through a dynamic (on-call) workforce in addition to the static workforce, (a) is capable of balancing risk between days and reducing overall risk better than the static model, (b) is scalable and capable of identifying the quantity and the right mix of analyst expertise in an organization, and (c) is able to determine their dynamic (on-call) schedule and their sensor-to-analyst allocation in order to maintain risk below a given upper bound. Several meta-principles are presented, which are derived from the optimization model, and they further serve as guiding principles for hiring and scheduling cybersecurity analysts. Days-off scheduling was performed to determine analyst weekly work schedules that met the cybersecurity system’s workforce constraints and requirements.