An Attribution of Cyberattack using Association Rule Mining (ARM)

被引:0
|
作者
Abu, Md Sahrom [1 ]
Ariffin, Aswami [1 ]
Selamat, Siti Rahayu [2 ]
Yusof, Robiah [2 ]
机构
[1] Cybersecur Malaysia, Malaysian Comp Emergency Response Team, Cyberjaya, Selangor De, Malaysia
[2] Univ Teknikal Malaysia Melaka, Fac Informat Technol & Commun, Durian Tunggal, Melaka, Malaysia
关键词
CTI; association rule mining; Apriori Algorithm; attribution; interestingness measures;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid development of computer networks and information technology, an attacker has taken advantage to manipulate the situation to launch a complicated cyberattack. This complicated cyberattack causes a lot of problems among the organization because it requires an effective cyberattack attribution to mitigate and reduce the infection rate. Cyber Threat Intelligence (CTI) has gain wide coverage from the media due to its capability to provide CTI feeds from various data sources that can be used for cyberattack attribution. In this paper, we study the relationship of basic Indicator of Compromise (IOC) based on a network traffic dataset from a data mining approach. This dataset is obtained using a crawler that is deployed to pull security feed from Shadowserver. Then an association analysis method using Apriori Algorithm is implemented to extract rules that can discover interesting relationship between large sets of data items. Finally, the extracted rules are evaluated over the factor of interestingness measure of support, confidence and lift to quantify the value of association rules generated with Apriori Algorithm. By implementing the Apriori Algorithm in Shadowserver dataset, we discover some association rules among several IOC which can help attribute the cyberattack.
引用
收藏
页码:352 / 358
页数:7
相关论文
共 50 条
  • [31] Application of Computational Verb Theory to Association Rule Mining
    Cai, Alian
    Yang, Tao
    2012 INTERNATIONAL CONFERENCE ON ANTI-COUNTERFEITING, SECURITY AND IDENTIFICATION (ASID), 2012,
  • [32] A Novel Algorithm for Association Rule Mining Without Candidate
    Zhou, Huanyin
    Liu, Jinsheng
    FIRST IITA INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, PROCEEDINGS, 2009, : 116 - +
  • [33] Data Mining Application using Association Rule Mining ECLAT Algorithm Based on SPMF
    Reynaldo, Jason
    Tonara, David Boy
    3RD INTERNATIONAL CONFERENCE ON ELECTRICAL SYSTEMS, TECHNOLOGY AND INFORMATION (ICESTI 2017), 2018, 164
  • [34] Rule Discovery from Breast Cancer Risk Factors using Association Rule Mining
    Kabir, Md Faisal
    Ludwig, Simone A.
    Abdullah, Abu Saleh
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 2433 - 2441
  • [35] Analysis of Association Between Students' Mathematics Test Results Using Association Rule Mining
    Park, SungSik
    Park, Young B.
    2018 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON18), 2018, : 73 - 76
  • [36] Association Rule Mining in Healthcare Analytics
    Hareendran, S. Anand
    Chandra, S. S. Vinod
    DATA MINING AND BIG DATA, DMBD 2017, 2017, 10387 : 31 - 39
  • [37] Optimization of Association Rule Mining Using Hybridized Artificial Bee Colony (ABC) with BAT Algorithm
    Neelima, S.
    Satyanarayana, N.
    Murthy, P. Krishna
    2017 7TH IEEE INTERNATIONAL ADVANCE COMPUTING CONFERENCE (IACC), 2017, : 831 - 834
  • [38] Association Rule Mining on Fragmented Database
    Hamzaoui, Amel
    Malluhi, Qutaibah
    Clifton, Chris
    Riley, Ryan
    DATA PRIVACY MANAGEMENT, AUTONOMOUS SPONTANEOUS SECURITY, AND SECURITY ASSURANCE, 2015, 8872 : 335 - 342
  • [39] Integration of OLAP and Association rule mining
    Bawane, Gunwanti R.
    Deshkar, Prarthana
    2015 INTERNATIONAL CONFERENCE ON INNOVATIONS IN INFORMATION, EMBEDDED AND COMMUNICATION SYSTEMS (ICIIECS), 2015,
  • [40] Discovering hidden patterns among medicines prescribed to patients using Association Rule Mining Technique
    Saha, Esha
    Rathore, Pradeep
    INTERNATIONAL JOURNAL OF HEALTHCARE MANAGEMENT, 2023, 16 (02) : 277 - 286