Network Data Collection, Fusion, Mining and Analytics for Cyber Security.

Zheng Yan
DOI: https://doi.org/10.1007/978-3-030-30619-9_1
2019-01-01
Abstract:Cyber security has become the most crucially important topic for safeguarding national and personal safety. Achieving cyber security depends not only on defense technologies, but also the technologies to detect and discover cyber intrusions, threats and attacks. Herein, network data plays an essential role. However, network data for security detection (i.e., security-related data) normally features big data characters. How to collect and process them in an efficient, effective and precise way becomes a big challenge towards network security measurement. In this article, I will introduce the current research results of my research team in terms of adaptive network data collection in heterogenous networks, data fusion and compression for highly efficient network intrusion detection and economic data storage, a method of application-layer tunnel detection with rules and machine learning, as well as data mining and analytics on opinions posted in the website for retrieving trust information and generating reputation. Working on security-related network data collection, fusion, mining and analytics, we make efforts to collect and process as few as possible data in a context-aware manner, but achieve as accurate as possible security detection results.
What problem does this paper attempt to address?