Clustering of Threat Information to Mitigate Information Overload for Computer Emergency Response Teams

10/25/2022
by   Philipp Kuehn, et al.
0

The constantly increasing number of threats and the existing diversity of information sources pose challenges for Computer Emergency Response Teams (CERTs). In order to respond to new threats, CERTs need to gather information in a timely and comprehensive manner. However, the volume of information and sources can lead to information overload. This paper answers the question of how to reduce information overload for CERTs with the help of clustering methods. Conditions for such a framework were established and subsequently tested. In order to perform an evaluation, different types of evaluation metrics were introduced and selected in relation to the framework conditions. Furthermore, different vectorizations and distance measures in combination with the clustering methods were evaluated and interpreted. Two different ground-truth datasets were used for the evaluation, one containing threat messages and a dataset with messages from different news categories. The work shows that the K-means clustering method along with TF-IDF vectorization and cosine distance provide the best results in the domain of threat messages.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/29/2018

Helping Crisis Responders Find the Informative Needle in the Tweet Haystack

Crisis responders are increasingly using social media, data and other di...
research
08/18/2022

LogKernel A Threat Hunting Approach Based on Behaviour Provenance Graph and Graph Kernel Clustering

Cyber threat hunting is a proactive search process for hidden threats in...
research
02/10/2021

DANTE: Predicting Insider Threat using LSTM on system logs

Insider threat is one of the most pernicious threat vectors to informati...
research
11/16/2021

A Comparative Study on Transfer Learning and Distance Metrics in Semantic Clustering over the COVID-19 Tweets

This paper is a comparison study in the context of Topic Detection on CO...
research
10/15/2021

Transformer-based Multi-task Learning for Disaster Tweet Categorisation

Social media has enabled people to circulate information in a timely fas...

Please sign up or login with your details

Forgot password? Click here to reset