Understanding the Relationship between Human Behavior and Susceptibility to Cyber Attacks: A Data-Driven Approach

被引:25
|
作者
Ovelgonne, Michael [1 ]
Dumitras, Tudor [1 ,2 ,3 ]
Prakash, B. Aditya [4 ]
Subrahmanian, V. S. [1 ,3 ,5 ]
Wang, Benjamin [4 ]
机构
[1] Univ Maryland, UMIACS, College Pk, MD 20740 USA
[2] Univ Maryland, Dept Elect Engn, College Pk, MD 20742 USA
[3] UMIACS, College Pk, MD USA
[4] Virginia Tech, Dept Comp Sci, Blacksburg, VA 24060 USA
[5] Univ Maryland, Dept Comp Sci, College Pk, MD 20742 USA
关键词
Malware; computer virus; user behavior; SYSTEMS SECURITY; SURFACE;
D O I
10.1145/2890509
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Despite growing speculation about the role of human behavior in cyber-security of machines, concrete data-driven analysis and evidence have been lacking. Using Symantec's WINE platform, we conduct a detailed study of 1.6 million machines over an 8-month period in order to learn the relationship between user behavior and cyber attacks against their personal computers. We classify users into 4 categories (gamers, professionals, software developers, and others, plus a fifth category comprising everyone) and identify a total of 7 features that act as proxies for human behavior. For each of the 35 possible combinations (5 categories times 7 features), we studied the relationship between each of these seven features and one dependent variable, namely the number of attempted malware attacks detected by Symantec on the machine. Our results show that there is a strong relationship between several features and the number of attempted malware attacks. Had these hosts not been protected by Symantec's anti-virus product or a similar product, they would likely have been infected. Surprisingly, our results show that software developers are more at risk of engaging in risky cyber-behavior than other categories.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] Data-Driven Approach for Detection of Physical Faults and Cyber Attacks in Manufacturing Motor Drives
    Yang, Bowen
    Ye, Jin
    Coshatt, Stephen
    Song, Wenzhan
    Zahiri, Feraidoon
    2022 IEEE ENERGY CONVERSION CONGRESS AND EXPOSITION (ECCE), 2022,
  • [2] Understanding the human in the design of cyber-human discovery systems for data-driven astronomy
    Fluke, C. J.
    Hegarty, S. E.
    Macmahon, C. O-M
    ASTRONOMY AND COMPUTING, 2020, 33
  • [3] Understanding the Truck Parking Behavior Using a Data-Driven Approach
    Xiaoqiang Kong
    Nicole Katsikides
    Jason Ryan Wallis
    William L. Eisele
    Yunlong Zhang
    Data Science for Transportation, 2024, 6 (3):
  • [4] A Data-Driven Approach to Cyber Risk Assessment
    Santini, Paolo
    Gottardi, Giuseppe
    Baldi, Marco
    Chiaraluce, Franco
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019 (1-8) : 1 - 8
  • [5] Detection of data-driven blind cyber-attacks on smart grid: A deep learning approach
    Mukherjee, Debottam
    SUSTAINABLE CITIES AND SOCIETY, 2023, 92
  • [6] Data-Driven Detection of Stealth Cyber-Attacks in DC Microgrids
    Takiddin, Abdulrahman
    Rath, Suman
    Ismail, Muhammad
    Sahoo, Subham
    IEEE SYSTEMS JOURNAL, 2022, 16 (04): : 6097 - 6106
  • [7] A data-driven approach for understanding the stages of schizophrenia
    Docherty, J
    Rodriguez, S
    Kosik-Gonzalez, C
    Bossie, C
    Gharabawi, G
    Siris, S
    NEUROPSYCHOPHARMACOLOGY, 2005, 30 : S123 - S124
  • [8] An integrated data-driven scheme for the defense of typical cyber-physical attacks
    Wu, Shimeng
    Jiang, Yuchen
    Luo, Hao
    Zhang, Jiusi
    Yin, Shen
    Kaynak, Okyay
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2022, 220
  • [9] Data-Driven Probabilistic Anomaly Detection for Electricity Market under Cyber Attacks
    Sun, Mucun
    Ren, Lingyu
    Chiang, Nai-yuan
    2021 AMERICAN CONTROL CONFERENCE (ACC), 2021, : 4586 - 4591
  • [10] The sensor-actuators stealthy cyber-attacks framework on networked control systems: A data-driven approach
    Xin, Liang
    Yang, Biao
    Long, Zhiqing
    ASIAN JOURNAL OF CONTROL, 2024, 26 (02) : 960 - 973