Risky business: Fine-grained data breach prediction using business profiles

Risky business: Fine-grained data breach prediction using business profiles
复制标题

有风险的业务:使用业务概况进行细粒度数据泄露预测

DOI:
--
复制
发表时间:
2016
影响因子:
3.9
通讯作者:
M. Liu
M. Liu
中科院分区:
--
文献类型:
--
作者:
Armin Sarabi;Parinaz Naghizadeh Ardabili;Yang Liu;M. Liu

文献摘要

被引文献

相似文献

本文旨在了解组织的业务细节是否以及在多大程度上可以帮助评估公司在经历数据泄露事件时的风险,以及其在多种事件类型上的风险分布,以便提供有效保护、检测和从不同形式的安全事件中恢复的指导方针。现有的数据泄露预测工作主要集中在网络事件上,以及分析不同事件类别风险分布的研究,最著名的是Verizon最新的数据泄露调查报告,该报告仅根据商业部门的信息提供建议。在本文中,我们将利用更广泛的公开可用业务详细信息集,对涉及任何形式的数据泄露和数据丢失的事件提供更细粒度的分析。具体来说,我们使用VERIS社区数据库(VCDB)中收集的报告,以及来自Alexa网络信息服务(AWIS)、开放目录项目(ODP)和Neustar公司的数据,来训练和测试一系列分类器/预测器。我们的研究结果表明,我们的特征集可以区分数据泄露的受害者和非受害者,其真阳性率为90%,假阳性率为11%,使其成为评估实体网络风险的有效工具。此外,我们表明,与单独使用业务部门信息相比,我们的方法可以为特定事件类型派生出更准确的风险分布,并允许组织关注更稀疏的事件集,从而通过更明智的优先级划分,在安全上花费更少的资源,从而实现相同级别的保护。
This article aims to understand if, and to what extent, business details about an organization can help to assess a company’s risk in experiencing data breach incidents, as well its distribution of risk over multiple incident types, in order to provide guidelines to effectively protect, detect, and recover from different forms of security incidents. Existing work on prediction of data breach mainly focuses on network incidents, and studies that analyze the distribution of risk across different incident categories, most notably Verizon’s latest Data Breach Investigations Report, provide recommendations based solely on business sector information. In this article, we leverage a broader set of publicly available business details to provide a more fine-grained analysis on incidents involving any form of data breach and data loss. Specifically, we use reports collected in the VERIS Community Database (VCDB), as well as data from Alexa Web Information Service (AWIS), the Open Directory Project (ODP), and Neustar Inc., to train and test a sequence of classifiers/predictors. Our results show that our feature set can distinguish between victims of data breaches, and nonvictims, with a 90% true positive rate, and 11% false positive rate, making them an effective tool in evaluating an entity’s cyber-risk. Furthermore, we show that compared to using business sector information alone, our method can derive a more accurate risk distribution for specific incident types, and allow organizations to focus on a sparser set of incidents, thus achieving the same level of protection by spending less resources on security through more judicious prioritization. Keywords : data breach; resource allocation; risk assessment.