结合技术和社交因素,精准预测黑客攻击风险。
STRisk: A Socio-Technical Approach to Assess Hacking Breaches Risk
- 融合技术指标与社交媒体数据构建组织风险画像
- AUC超98%,较仅用技术特征提升12%
- 揭示开放端口、证书过期等关键风险点
数据泄露正呈现新态势,其预测对组织至关重要。现有研究多从技术角度出发,忽视了社交媒体等社会因素的影响。为此,我们提出STRisk,一种融合社会-技术维度的预测系统。研究覆盖超过3800家美国组织(含受害与非受害方),为每家组织构建包含多种外部可测技术指标和社会因素的综合画像。针对未报告事件带来的样本噪声问题,我们提出噪声校正方法以修正误标组织。基于此,构建多个机器学习模型预测组织是否面临黑客攻击。结果表明,同时使用技术与社会特征时,曲线下面积(AUC)超过98%,比仅使用技术特征高12%。特征重要性分析显示,开放端口和过期证书是最佳技术预测因子,而传播力与认同度是最佳社会预测因子。
原文摘要 · Abstract (English)
Data breaches have begun to take on new dimensions and their prediction is becoming of great importance to organizations. Prior work has addressed this issue mainly from a technical perspective and neglected other interfering aspects such as the social media dimension. To fill this gap, we propose STRisk which is a predictive system where we expand the scope of the prediction task by bringing into play the social media dimension. We study over 3800 US organizations including both victim and non-victim organizations. For each organization, we design a profile composed of a variety of externally measured technical indicators and social factors. In addition, to account for unreported incidents, we consider the non-victim sample to be noisy and propose a noise correction approach to correct mislabeled organizations. We then build several machine learning models to predict whether an organization is exposed to experience a hacking breach. By exploiting both technical and social features, we achieve a Area Under Curve (AUC) score exceeding 98%, which is 12% higher than the AUC achieved using only technical features. Furthermore, our feature importance analysis reveals that open ports and expired certificates are the best technical predictors, while spreadability and agreeability are the best social predictors.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。