Poster: Analysis and parsing of unstructured cyber-security incident data

1Citations
Citations of this article
26Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The latest threat intelligence platforms use structured protocols to share and analyze cyber-security data. However, most of this data is reported to the platform in the form of unstructured text such as social media posts, emails, and news articles, which then require manual conversion to structured form. In order to bridge the gap between unstructured and structured data, we propose to implement a natural-language-processing-(NLP)-based information extraction (IE) system that takes texts within the cyber-security domain and parses them into structured format. Our approach targets the VERIS format and makes use of the VERIS Community Database as a source of unstructured texts-primarily consisting of news articles-and their structured counterparts (VERIS reports).We propose first to use a supervised machine learning (ML) classifier to discriminate between cyber-related and non-cyber-related texts, and then to use ML classifiers decide which VERIS parameters are relevant in a given text. Then, we propose to use NLP and IE techniques to extract tuples of grammatically co-dependent words. Finally, these tuples will be passed to a domain- and field-specific IE components to fill in different fields of an output VERIS report.

Cite

CITATION STYLE

APA

Ochoa, A. J., & Finlayson, M. A. (2019). Poster: Analysis and parsing of unstructured cyber-security incident data. In WiSec 2019 - Proceedings of the 2019 Conference on Security and Privacy in Wireless and Mobile Networks (pp. 345–346). Association for Computing Machinery, Inc. https://doi.org/10.1145/3317549.3326324

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free