You are currently viewing Network security situation awareness forecasting based on statistical approach and neural networks

Network security situation awareness forecasting based on statistical approach and neural networks

Article
Link to Science Direct

Authors:  Pavol Sokol, Richard Staňa, Andrej Gajdoš, Patrik Pekarčík

Abstract

The usage of new and progressive technologies brings with it new types of security threats and security incidents. Their number is constantly growing.The current trend is to move from reactive to proactive activities. For this reason, the organization should be aware of the current security situation, including the forecasting of the future state. The main goal of organizations, especially their security operation centres, is to handle events, identify potential security incidents, and effectively forecast the network security situation awareness (NSSA). In this paper, we focus on increasing the efficiency of utilization of this part of cybersecurity. The paper’s main aim is to compare selected statistical models and models based on neural networks to find out which models are more suitable for NSSA forecasting. Based on the analysis provided in this paper, neural network methods prove a more accurate alternative than classical statistical prediction models in NSSA forecasting. In addition, the paper analyses the selection criteria and suitability of time series, which do not only reflect information about the total number of security events but represent a category of security event (e.g. recon scanning), port or protocol.