Massachusetts Institute of Technology
Using Machine Learning for Description and Inference of Cyber Threats, Vulnerabilities, and Mitigations
Abstract
dc:description.abstractMachine learning and natural language processing (NLP) can help describe and make inferences on the vast amount of text data in cybersecurity. We use a graph database named BRON, which contains data from publicly available threat and vulnerability sources, for machine learning inference. Applying machine learning to BRON can provide us with more robust relationships, which can improve defenses against cyber threats. We experiment with different feature representations and subsets of the data, and show that machine learning and NLP can effectively classify edges between entries from different data sources as well as predict possible edge candidates. Experts agree that several of our predicted candidates are plausible edges. We also analyze defensive mitigation similarities using NLP techniques and find that there are identical mitigation descriptions for some entries that have internal relationships.
Degree
thesis:*- Name thesis:degree_name
- Master
- Department dc:contributor.department
- Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
- Grantor dc:publisher
- Massachusetts Institute of Technology
- Year dc:date.issued
- 2022
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Srinivasan, Ashwin
- Advisors dc:contributor.advisor
-
- Hemberg, Erik
- O’Reilly, Una-May
Rights
dc:rights- Statement dc:rights
-
- In Copyright - Educational Use Permitted
- Copyright MIT
- Licence dc:rights.uri
Identifiers
dc:identifier.*- Handle dc:identifier.uri
- https://hdl.handle.net/1721.1/143257
- OAI identifier oai:identifier
- oai:dspace.mit.edu:1721.1/143257