Skip to main navigation Skip to search Skip to main content

A Modular Approach to Automatic Cyber Threat Attribution using Opinion Pools

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

180 Downloads (Pure)

Abstract

Cyber threat attribution can play an important role in increasing resilience against digital threats. Recent research focuses on automating the threat attribution process and on integrating it with other efforts, such as threat hunting. To support increasing automation of the cyber threat attribution process, this paper proposes a modular architecture as an alternative to current monolithic automated approaches. The modular architecture can utilize opinion pools to combine the output of concrete attributors. The proposed solution increases the tractability of the threat attribution problem and offers increased usability and interpretability, as opposed to monolithic alternatives. In addition, a Pairing Aggregator is proposed as an aggregation method that forms pairs of attributors based on distinct features to produce intermediary results before finally producing a single Probability Mass Function (PMF) as output. The Pairing Aggregator sequentially applies both the logarithmic opinion pool and the linear opinion pool. An experimental validation suggests that the modular approach does not result in decreased performance and can even enhance precision and recall compared to monolithic alternatives. The results also suggest that the Pairing Aggregator can improve precision over the linear and logarithmic opinion pools. Furthermore, the improved k-accuracy in the experiment suggests that forensic experts can leverage the resulting PMF during their manual attribution processes to enhance their efficiency.
Original languageEnglish
Title of host publication2023 IEEE International Conference on Big Data, Big Data 2023
EditorsJingrui He, Themis Palpanas, Xiaohua Hu, Alfredo Cuzzocrea, Dejing Dou, Dominik Slezak, Wei Wang, Aleksandra Gruca, Jerry Chun-Wei Lin, Rakesh Agrawal
PublisherInstitute of Electrical and Electronics Engineers
Pages3089-3098
Number of pages10
ISBN (Electronic)979-8-3503-2445-7
DOIs
Publication statusPublished - 22 Jan 2024
Event2023 IEEE International Conference on Big Data - Sorrento, Italy
Duration: 15 Dec 202318 Dec 2023
https://bigdataieee.org/BigData2023/index.html

Conference

Conference2023 IEEE International Conference on Big Data
Abbreviated titleIEEE BigData 2023
Country/TerritoryItaly
CitySorrento
Period15/12/2318/12/23
Internet address

Funding

This publication is part of the project CATRIN (with project number NWA.1215.18.003) and the project INTERSECT (with project number NWA.1160.18.301) of the research program Cybersecurity which are (partly) financed by the Dutch Research Council (NWO). For the purpose of Open Access, a CC-BY 4.0 public copyright license is applied to any Author Accepted Manuscript version arising from this submission.

FundersFunder number
Nederlandse Organisatie voor Wetenschappelijk OnderzoekNWA.1215.18.003, NWA.1160.18.301

    UN SDGs

    This output contributes to the following UN Sustainable Development Goals (SDGs)

    1. SDG 16 - Peace, Justice and Strong Institutions
      SDG 16 Peace, Justice and Strong Institutions

    Keywords

    • Cyber Threat Attribution
    • Modular Architecture
    • Opinion Pools
    • Cyber Threat Intelligence
    • Digital Forensics

    Fingerprint

    Dive into the research topics of 'A Modular Approach to Automatic Cyber Threat Attribution using Opinion Pools'. Together they form a unique fingerprint.

    Cite this