Optimizing Cybersecurity Operations Using Data-driven Intelligence

Graduation Year

2024

Document Type

Dissertation

Degree

Ph.D.

Degree Name

Doctor of Philosophy (Ph.D.)

Degree Granting Department

Industrial and Management Systems Engineering

Major Professor

Ankit Shah, Ph.D.

Committee Member

Tapas K. Das, Ph.D.

Committee Member

Trung Le, Ph.D.

Committee Member

Nasir Ghani, Ph.D.

Committee Member

Balaji Padmanabhan, Ph.D.

Keywords

Alert Management, Graph Representation Learning, Network Intrusion Detection Systems, Real-time Intrusion Detection

Abstract

Cybersecurity operations centers (CSOCs) play a crucial role in safeguarding organizations from cyber threats. CSOC operations are divided into two main areas: Intrusion detection systems (IDS) and security response team (SRT) operations. Machine learning (ML) and deep learning (DL) advancements have significantly improved IDSs. IDS can be either flow-based, suitable for offline analysis, or packet-based, which analyze traffic in real-time. However, packet-based IDS often treat packets independently, ignoring the sequential nature of network communication. Additionally, recent ML/DL approaches also struggle with capturing global and structural information and novel attack detection due to their reliance on labeled data. The SRT within CSOCs is tasked with investigating and mitigating alerts. A significant challenge here is the imbalance between the volume of alerts and the number of available analysts, causing a backlog that can leave the network vulnerable. Delays in alert investigation persist due cognitive burden on analysts from reviewing unrelatedalerts and mismatches between alerts and analyst expertise. The overarching goal of this dissertation is to develop data-driven artificial intelligence (AI) models and solutions to address limitations in IDS and SRT operations. For IDS, we propose novel frameworks based on convolutional neural networks and graph representation learning for packet-based IDS, effectively analyzing packet data and considering temporal, structural, and global information among packets. For SRT, we propose a framework utilizing machine learning and optimization methods to dynamically improve throughput during alert investigation work. The insights gained will benefit CSOCs by providing efficient and accurate real-time anomaly and attack detection for IDS and optimizing alert management throughout SRT operations.

This document is currently not available here.

Share

COinS