Multi-labeling with topic models for searching security information

被引:0
作者
Osada, Yuki [1 ]
Nagasawa, Ryusei [1 ]
Shiraishi, Yoshiaki [1 ]
Takita, Makoto [2 ]
Furumoto, Keisuke [3 ]
Takahashi, Takeshi [3 ]
Mohri, Masami [4 ]
Morii, Masakatu [1 ]
机构
[1] Kobe Univ, Nada Ku, 1-1 Rokkodai Cho, Kobe, Hyogo 6578501, Japan
[2] Univ Hyogo, Nishi Ku, 8-2-1 Gakuennishi Machi, Kobe, Hyogo 6512197, Japan
[3] Natl Inst Informat & Commun Technol, 4-2-1 Nukui Kitamachi, Koganei, Tokyo 1848795, Japan
[4] Kindai Univ, 3-4-1 Kowakae, Higashiosaka, Osaka 5778501, Japan
关键词
Multi-labeling; Security reports; Threat intelligence; Topic models;
D O I
10.1007/s12243-022-00928-5
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
Security information such as threat information and vulnerability information are utilized to analyze cyberattacks. If specific keywords such as the name of malware related to the event to be analyzed are known in advance, it is possible to obtain information using typical search engines. However, when a security operator cannot recall appropriate keywords related to the event to be analyzed, or when a commonly recognized identifier does not exist, a general search engine cannot be expected to produce useful results. In this paper, we propose a method using topic models and outlier detection to generate multi-labels for search, with the goal of constructing a search engine that can present relevant security information even in such situations. In addition, this paper discusses the application of the proposed method to 2386 security reports issued from 2017 to 2019 to demonstrate that the labeling can be focused on specific topics.
引用
收藏
页码:777 / 788
页数:12
相关论文
共 18 条
  • [1] [Anonymous], CISCO BLOG
  • [2] [Anonymous], SYMANTEC BLOGS
  • [3] [Anonymous], TMTOOLKIT PYPL
  • [4] [Anonymous], PALO ALTO NETWORKS B
  • [5] [Anonymous], NETWORK SECURITY BLO
  • [6] [Anonymous], BARRACUDASECURITY AC
  • [7] [Anonymous], THREAT RES
  • [8] [Anonymous], SIMPLY SECURITY NEWS
  • [9] Arun R, 2010, LECT NOTES ARTIF INT, V6118, P391
  • [10] Latent Dirichlet allocation
    Blei, DM
    Ng, AY
    Jordan, MI
    [J]. JOURNAL OF MACHINE LEARNING RESEARCH, 2003, 3 (4-5) : 993 - 1022