Graphing Website Relationships for Risk Prediction: Identifying Derived Threats to Users Based on Known Indicators

03/02/2020
by   Philip H. Kulp, et al.
0

The hypothesis for the study was that the relationship based on referrer links and the number of hops to a malicious site could indicate the risk to another website. We chose Receiver Operating Characteristics (ROC) analysis as the method of comparing true positive and false positive rates for captured web traffic to test the predictive capabilities of our model. Known threat indicators were used as designators, and the Neo4j graph database was leveraged to map the relationships between other websites based on referring links. Using the referring traffic, we mapped user visits across websites with a known relationship to track the rate at which users progressed from a non-malicious website to a known threat. The results were grouped by the hop distance from the known threat to calculate the predictive rate. The results of the model produced true positive rates between 58.59 between 7.42 suggest an improved performance based on the closer proximity from the known threat, while an increased referring distance from the threat resulted in higher rates of false positives.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/04/2019

Combining Biomarkers by Maximizing the True Positive Rate for a Fixed False Positive Rate

Biomarkers abound in many areas of clinical research, and often investig...
research
04/01/2019

ScriptNet: Neural Static Analysis for Malicious JavaScript Detection

Malicious scripts are an important computer infection threat vector in t...
research
10/01/2022

Explaining Website Reliability by Visualizing Hyperlink Connectivity

As the information on the Internet continues growing exponentially, unde...
research
09/19/2023

The Impact of Exposed Passwords on Honeyword Efficacy

Honeywords are decoy passwords that can be added to a credential databas...
research
02/16/2022

CGraph: Graph Based Extensible Predictive Domain Threat Intelligence Platform

Ability to effectively investigate indicators of compromise and associat...
research
01/12/2018

A Quantitative Approach in Heuristic Evaluation of E-commerce Websites

This paper presents a pilot study on developing an instrument to predict...
research
05/15/2018

Neural Classification of Malicious Scripts: A study with JavaScript and VBScript

Malicious scripts are an important computer infection threat vector. Our...

Please sign up or login with your details

Forgot password? Click here to reset