Traditional security monitoring systems may struggle with detecting advanced and novel cyber threats, especially as cyberattacks are becoming more sophisticated. As a consequence, there is a growing need for advanced techniques to improve defense mechanisms. Among these, Artificial Intelligence (AI) has emerged as a promising solution. The paper explores the growing popularity of AI technologies in cybersecurity and investigates three distinct methodologies aimed at improving attack detection criteria within security monitoring systems. The first methodology is based on the extraction and analysis of correlation indexes between features and target variables, enabling the identification of recurring patterns indicative of anomalies. Secondly, Association Rule Mining (ARM) is utilized to identify hidden patterns and relationships between features, leading to more accurate detection criteria. Lastly, explainable AI (xAI) is leveraged to mine advanced rules, as well as increase the transparency of the model, enabling security analysts to understand the decision-making process behind threat detection. Through a comparative analysis, the efficacy of each method is evaluated in terms of detection accuracy, precision, recall, and F1-score. Promising experimental results demonstrate the potential of AI-driven approaches to enhance the capabilities of security monitoring systems, providing organizations with a new layer of protection against an evolving threat landscape.

Comparative Analysis of AI-Based Methods for Enhancing Cybersecurity Monitoring Systems

Uccello, Federica;D'Antonio, Salvatore;
2024-01-01

Abstract

Traditional security monitoring systems may struggle with detecting advanced and novel cyber threats, especially as cyberattacks are becoming more sophisticated. As a consequence, there is a growing need for advanced techniques to improve defense mechanisms. Among these, Artificial Intelligence (AI) has emerged as a promising solution. The paper explores the growing popularity of AI technologies in cybersecurity and investigates three distinct methodologies aimed at improving attack detection criteria within security monitoring systems. The first methodology is based on the extraction and analysis of correlation indexes between features and target variables, enabling the identification of recurring patterns indicative of anomalies. Secondly, Association Rule Mining (ARM) is utilized to identify hidden patterns and relationships between features, leading to more accurate detection criteria. Lastly, explainable AI (xAI) is leveraged to mine advanced rules, as well as increase the transparency of the model, enabling security analysts to understand the decision-making process behind threat detection. Through a comparative analysis, the efficacy of each method is evaluated in terms of detection accuracy, precision, recall, and F1-score. Promising experimental results demonstrate the potential of AI-driven approaches to enhance the capabilities of security monitoring systems, providing organizations with a new layer of protection against an evolving threat landscape.
2024
9783031652226
9783031652233
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11367/168803
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 2
  • ???jsp.display-item.citation.isi??? ND
social impact