Optimizing Cybersecurity Operations Using Data-driven Intelligence
Graduation Year
2024
Document Type
Dissertation
Degree
Ph.D.
Degree Name
Doctor of Philosophy (Ph.D.)
Degree Granting Department
Industrial and Management Systems Engineering
Major Professor
Ankit Shah, Ph.D.
Committee Member
Tapas K. Das, Ph.D.
Committee Member
Trung Le, Ph.D.
Committee Member
Nasir Ghani, Ph.D.
Committee Member
Balaji Padmanabhan, Ph.D.
Keywords
Alert Management, Graph Representation Learning, Network Intrusion Detection Systems, Real-time Intrusion Detection
Abstract
Cybersecurity operations centers (CSOCs) play a crucial role in safeguarding organizations from cyber threats. CSOC operations are divided into two main areas: Intrusion detection systems (IDS) and security response team (SRT) operations. Machine learning (ML) and deep learning (DL) advancements have significantly improved IDSs. IDS can be either flow-based, suitable for offline analysis, or packet-based, which analyze traffic in real-time. However, packet-based IDS often treat packets independently, ignoring the sequential nature of network communication. Additionally, recent ML/DL approaches also struggle with capturing global and structural information and novel attack detection due to their reliance on labeled data. The SRT within CSOCs is tasked with investigating and mitigating alerts. A significant challenge here is the imbalance between the volume of alerts and the number of available analysts, causing a backlog that can leave the network vulnerable. Delays in alert investigation persist due cognitive burden on analysts from reviewing unrelatedalerts and mismatches between alerts and analyst expertise. The overarching goal of this dissertation is to develop data-driven artificial intelligence (AI) models and solutions to address limitations in IDS and SRT operations. For IDS, we propose novel frameworks based on convolutional neural networks and graph representation learning for packet-based IDS, effectively analyzing packet data and considering temporal, structural, and global information among packets. For SRT, we propose a framework utilizing machine learning and optimization methods to dynamically improve throughput during alert investigation work. The insights gained will benefit CSOCs by providing efficient and accurate real-time anomaly and attack detection for IDS and optimizing alert management throughout SRT operations.
Scholar Commons Citation
Ghadermazi, Jalal, "Optimizing Cybersecurity Operations Using Data-driven Intelligence" (2024). USF Tampa Graduate Theses and Dissertations.
https://digitalcommons.usf.edu/etd/11126
