The scale of Internet-connected systems has increased considerably, and these systems are being exposed to cyber attacks more than ever. The complexity and dynamics of cyber attacks require protecting mechanisms to be responsive, adaptive, and scalable. Machine learning, or more specifically deep reinforcement learning…
This paper discusses adversarial attacks on cyber security systems using machine learning.
problem Adversarial attacks limit the use of machine learning in cyber security.
method Characterizes adversarial attack methods and their applications in cyber security.
result Highlights unique challenges and future research directions for adversarial attacks in cyber security.
We present cyber-security problems of high importance. We show that in order to solve these cyber-security problems, one must cope with certain machine learning challenges. We provide novel data sets representing the problems in order to enable the academic community to investigate the problems and suggest methods to c…
The paper uses a simulator and optimisation to defend against cyber threats.
problem Defending against cyber threats in simulated networks.
method Dynamic causal Bayesian optimisation (DCBO) integrated with a cyber security simulator.
result DCBO optimally reduces the cost of intrusions in simulated networks.
Framework detects cyber threats from Twitter tweets.
problem Time-consuming manual extraction of cyber threat intelligence.
method Novelty detection model trained on CVE data.
result F1-score of 0.643 for classifying cyber threat tweets.
Paper offers guidelines for using ML in cyber security, focusing on botnet detection.
problem Lack of public benchmark datasets for evaluating ML-based cyber security systems.
method Provided concrete guidelines and recommendations for using supervised ML in cyber security, focusing on botnet detection.
result Ensemble models are well-suited to handle class imbalance in botnet detection.
Recent changes to greenhouse gas emission policies are catalyzing the electric vehicle (EV) market making it readily accessible to consumers. While there are challenges that arise with dense deployment of EVs, one of the major future concerns is cyber security threat. In this paper, cyber security threats in the form o…
A novel model combines deep learning and extreme value theory for multivariate cyber risk prediction.
problem High dimensionality and heavy tails in multivariate cyber risk patterns.
method Combines deep learning for point predictions and extreme value theory for quantile predictions.
result The model provides satisfactory high quantile predictions and accurate point predictions.
This paper optimizes cybersecurity resource allocation in networks with heterogeneous attacker and defender valuations.
problem Optimizing cybersecurity resource allocation in networks with heterogeneous attacker and defender valuations.
method Combining strategic behavior of players with contagion dynamics, a method is extended to determine optimal resource allocation based on simple network metrics weighted by risk profiles.
result The asymmetry between attacker and defender valuations drives optimal attack and defense strategies, shaping system resilience.
Research shows filtering reduces predictability of cyber-attacks.
problem Predicting cyber-attacks from incomplete data.
method Combining external data with machine learning algorithms to learn indicators of cyber-attacks.
result The process of filtering reduces the predictability of cyber-attacks.
Introduces an artificial cyber lab to test and identify cyber resilience measures.
problem Systemic cyber risks and their control methods.
method Classical contagion models and artificial cyber lab simulations.
result Identified two classes of measures: security- and topology-based interventions.
Paper tackles cybersecurity attack detection with an ensemble approach.
problem Challenges in multi-class classification for cyber security breaches.
method Designing a multi-node multi-class classification ensemble approach.
result Proposed approach outperforms full-data approach in multi-node data-censoring cases.
Study examines cyber losses across sectors, finds high severity and frequency.
problem Understanding the nature of cyber losses and their variability across sectors.
method Analysis of a leading industry dataset of cyber events, focusing on frequency and severity.
result Cyber risks are heavy-tailed, with high probability of extreme losses.
This research develops a new model for cyber risk and insurance pricing.
problem Accurate calculation of aggregate losses in cyber insurance pricing.
method A path-based k-generation risk contagion model in a tree-shaped network structure.
result Explicit expressions for mean and variance of local loss on a single path.
Intrusion detection systems (IDSs) generate valuable knowledge about network security, but an abundance of false alarms and a lack of methods to capture the interdependence among alerts hampers their utility for network defense. Here, we explore a graph-based approach for fusing alerts generated by multiple IDSs (e.g.,…
GANs generate realistic cyber-attack alerts with feature dependencies.
problem Challenges in creating realistic cyber-attack alert data.
method Used Generative Adversarial Networks (GANs) to learn complex data distributions.
result GANs successfully generate realistic alerts with feature dependencies.
Extends random dot product graph model to handle multiple graphs.
problem Modeling and analyzing multiple graphs with shared nodes.
method Jointly embed adjacency matrices into a latent space.
result Node representations converge to latent positions with Gaussian error.
The exponential increase in dependencies between the cyber and physical world leads to an enormous amount of data which must be efficiently processed and stored. Therefore, computing paradigms are evolving towards machine learning (ML)-based systems because of their ability to efficiently and accurately process the eno…
Devign uses graph neural networks to identify vulnerabilities efficiently.
problem Challenging and tedious process of identifying vulnerabilities in software systems.
method Devign employs a graph neural network to classify graph-level vulnerabilities using comprehensive code semantic representations.
result Devign significantly outperforms state-of-the-art models in vulnerability identification.
Adversarial attacks hide cyber-physical attacks in ICS.
problem Hiding cyber-physical attacks in industrial control systems.
method Modeling an attacker compromising sensors, manipulating data, and evaluating attacks on both continuous and mixed data.
result Successfully hides cyber-physical attacks with 2.87 out of 12 sensors compromised on average.
MEG models for dynamic networks estimate dependencies and shared latent space relationships.
problem Modeling dynamic networks with shared latent space relationships and dependencies.
method MEG combines mutually exciting point processes and latent space models to estimate node-specific parameters and unobserved edges.
result MEG models can estimate intensities for unobserved edges, useful for anomaly detection in real-world applications.
Cyber security has grown up to be a hot issue in recent years. How to identify potential malware becomes a challenging task. To tackle this challenge, we adopt deep learning approaches and perform flow detection on real data. However, real data often encounters an issue of imbalanced data distribution which will lead t…
ACE explains security anomaly detection models through feature contributions.
problem Understanding which features contribute to security anomalies.
method Regression framework to locally approximate anomaly scores.
result Identifies correct contributing features in synthetic data and real data.
The future Internet of Things (IoT) will have a deep economical, commercial and social impact on our lives. The participating nodes in IoT networks are usually resource-constrained, which makes them luring targets for cyber attacks. In this regard, extensive efforts have been made to address the security and privacy is…
Machine Learning improves cybersecurity by detecting cyber attacks.
problem Growing sophistication and complexity of cybersecurity threats.
method Examined five machine learning algorithms on NetFlow datasets to classify malicious traffic.
result Random Forest Classifier detects over 95% of botnets in 8 out of 13 scenarios.
Blockchain aims to improve trust in AI systems, but lacks systematic studies.
problem Lack of systematic studies on blockchain design principles for AI trust.
method Hybrid qualitative and quantitative studies.
result Vast opportunities for future research and practice in blockchain design.
This work develops secure distributed algorithms for machine learning to protect against data poisoning and network attacks.
problem Vulnerability of distributed machine learning algorithms to cyber threats.
method Game-theoretic framework to capture conflicting goals of a learner and an attacker, iterative distributed algorithm.
result Distributed SVM is prone to fail in different types of attacks, with impact depending on network structure and attack capabilities.
Study proposes framework for cyber bonds to compensate cyber attack losses.
problem Cyber risk treatment in finance industry.
method Developed a framework, used publicly available data to determine loss distribution parameters, numerically simulated bond price and characteristics, considered two coupon calculation approaches.
result Numerical simulations of cyber bond price, yield, and characteristics.
Study finds stocks with higher cyber risk scores outperform others, indicating a market-wide cyber risk premium.
problem Identifying and quantifying firms' cyber risks and their impact on stock performance.
method Machine learning algorithm to analyze disclosures and a dedicated cyber corpus.
result High cyber risk stocks significantly outperform others, indicating a market-wide cyber risk premium.
Paper analyzes cyber risk classifications for forecasting performance.
problem Lack of effective out-of-sample forecasting performance in current cyber risk classifications.
method Rolling window analysis using threshold weighted scoring functions.
result Dynamic and impact-based cyber risk classifiers outperform others in forecasting future cyber risk losses.
Develops a Bonus-Malus model for cyber risk insurance to incentivize cybersecurity.
problem Lack of effective insurance strategies to incentivize cybersecurity.
method Proposes a Bonus-Malus model and a mathematical model with a numerical algorithm.
result Demonstrates how a Bonus-Malus system resolves moral hazard and benefits the insurer.
Paper introduces a framework for managing cyber risk with insurance and cybersecurity models.
problem Pervasive challenges in managing cyber risk, especially for capital allocation.
method Combines insurance frequency-severity models with cybersecurity cascade models for comprehensive cyber risk assessment. Facilitates informed capital allocation through a two-pillar framework.
result Demonstrates the necessity of comprehensive cost-benefit analysis for budget-constrained companies.
The paper models and prices cyber insurance risks, distinguishing idiosyncratic, systematic, and systemic risks.
problem Modeling and pricing cyber insurance policies, especially for systemic risks.
method Distinguishes three types of cyber risks and proposes methods for their valuation.
result Complex methods are needed for systemic cyber risks, including risk-neutral valuation and monetary risk measures.
Adversarial neural network improves cyber attack detection across different networks.
problem Detecting cyber attacks across networks with different traffic distributions.
method Adversarial Siamese neural network that learns invariant attack representations.
result The method retrieves sizable proportions of malicious events, even when trained on one dataset and tested on another.
Deep learning detects cyber-attacks in smart grid systems.
problem Cyber-attacks on smart grid systems.
method Deep learning-based intrusion detection system trained on industrial dataset.
result Proposed system outperforms Naive Bayes, SVM, and Random Forest.
Research designs an AI system to classify malware under adversarial conditions.
problem Adversarial attacks on malware classification algorithms.
method Machine learning-based intelligent systems approach.
result Robust malware classification model under adversarial conditions.
Study on cyber insurance viability using statistical models.
problem Exploring insurability of cyber risk and its factors.
method Regression models (GAMLSS, ordinal regressions) and utility modelling.
result Provides insights into insurability of cyber risk.
To assure cyber security of an enterprise, typically SIEM (Security Information and Event Management) system is in place to normalize security event from different preventive technologies and flag alerts. Analysts in the security operation center (SOC) investigate the alerts to decide if it is truly malicious or not. H…
Nowadays more and more data are gathered for detecting and preventing cyber attacks. In cyber security applications, data analytics techniques have to deal with active adversaries that try to deceive the data analytics models and avoid being detected. The existence of such adversarial behavior motivates the development…
Cyber-Physical Systems (CPSs) have been pervasive including smart grid, autonomous automobile systems, medical monitoring, process control systems, robotics systems, and automatic pilot avionics. As usually implemented on embedded devices, CPS is typically constrained by computation capacity and energy consumption. In …
Study finds high cyber risk stocks generate significant excess returns.
problem Understanding and quantifying cyber risk's impact on stock returns.
method Machine learning algorithm measuring cyber risk proximity to a corpus.
result High cyber risk stocks generate an excess return of 18.72% p.a.
The paper examines the feasibility of managing aggregate cyber-risk in IoT environments.
problem Determining sustainable conditions for providing aggregate cyber-risk coverage.
method Developed a rigorous general theory and validated it with real data.
result Conditions for sustainable aggregate cyber-risk management under heavy-tailed distributions.
Optimizes COVID-19 testing policy using a Multi-Armed Bandit approach.
problem Balancing discovery of positive cases with population surveillance.
method Risk scoring and random sampling based on Multi-Armed Bandit theory.
result Effective prioritization captures 65-92% of positive cases with varying testing capacity.
Most real-world data are scattered across different companies or government organizations, and cannot be easily integrated under data privacy and related regulations such as the European Union's General Data Protection Regulation (GDPR) and China' Cyber Security Law. Such data islands situation and data privacy & secur…
Paper proposes SDS for 5G security using machine learning.
problem Cybersecurity threats and expanding IoT in 5G networks.
method SDS uses machine learning, specifically a CNN with NAS, to detect anomalies.
result CNN achieved 100% accuracy in identifying benign traffic and 96.4% in detecting anomalies.
Enhances cyber risk assessment with entity-specific features.
problem Lack of high-quality public cyber incident data.
method Develops an InsurTech framework to enrich cyber incident data with entity-specific attributes and implements machine learning models.
result InsurTech features improve prediction robustness and provide customized risk profiles.
Study quantifies model risk in cyber insurance, affecting premium pricing.
problem Model risk and risk sensitivity in cyber insurance pricing.
method Robust estimators for model parameters and dependence analysis.
result Robust estimation improves tail index and joint loss model accuracy.
This paper aims to optimize incident-specific cyber insurance design.
problem Complexity in determining optimal risk retention and transfer.
method Economic foundation for incident-specific cyber insurance with Pareto optimality.
result Illustrates feasibility of designing incident-specific indemnities for both parties.