Using Machine Learning for Description and Inference of Cyber Threats, Vulnerabilities, and Mitigations
Name
Srinivasan-ashwins-meng-eecs-2022-thesis.pdf
Description
Thesis PDF
Size
967.38 KB
Format
Adobe PDF
Checksum (MD5)
ce0840d36adef9d652c7405d51b72f6a
Author(s)
Srinivasan, Ashwin
Advisor(s)
Hemberg, Erik
O’Reilly, Una-May
Date Issued
February 2022
Publisher
Massachusetts Institute of Technology
Abstract
Machine learning and natural language processing (NLP) can help describe and make inferences on the vast amount of text data in cybersecurity. We use a graph database named BRON, which contains data from publicly available threat and vulnerability sources, for machine learning inference. Applying machine learning to BRON can provide us with more robust relationships, which can improve defenses against cyber threats. We experiment with different feature representations and subsets of the data, and show that machine learning and NLP can effectively classify edges between entries from different data sources as well as predict possible edge candidates. Experts agree that several of our predicted candidates are plausible edges. We also analyze defensive mitigation similarities using NLP techniques and find that there are identical mitigation descriptions for some entries that have internal relationships.
MIT Department
Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science
Terms of Use
In Copyright - Educational Use Permitted
Copyright MIT
Persistent DSpace Link