Network security situation awareness forecasting based on statistical approach and neural networks

Pavol Sokol,Richard Staňa,Andrej Gajdoš,Patrik Pekarčík
DOI: https://doi.org/10.1093/jigpal/jzac024
2022-02-24
Abstract:Abstract The usage of new and progressive technologies brings with it new types of security threats and security incidents. Their number is constantly growing.The current trend is to move from reactive to proactive activities. For this reason, the organization should be aware of the current security situation, including the forecasting of the future state. The main goal of organizations, especially their security operation centres, is to handle events, identify potential security incidents, and effectively forecast the network security situation awareness (NSSA). In this paper, we focus on increasing the efficiency of utilization of this part of cybersecurity. The paper’s main aim is to compare selected statistical models and models based on neural networks to find out which models are more suitable for NSSA forecasting. Based on the analysis provided in this paper, neural network methods prove a more accurate alternative than classical statistical prediction models in NSSA forecasting. In addition, the paper analyses the selection criteria and suitability of time series, which do not only reflect information about the total number of security events but represent a category of security event (e.g. recon scanning), port or protocol.
mathematics, applied,logic
What problem does this paper attempt to address?