A Study of Discovering Security Trends from News Analysis
Year, semester
Number of pages
Advisory Committee
Date of Exam
Date of Submission
event detection, topic model, cluster analysis, CTI, text mining
有鑑於此,本研究提出一套新興資安情資偵測系統(Emerging Security Event Detection,簡稱ESED),自動化蒐集資安新聞,擷取資安事件關鍵字,透過主題模型與分群演算法分析新聞內容,以二階段分群與相似度比對方式偵測新興資安事件。經實驗結果顯示,本研究所提出之自動化新興資安情資偵測系統(ESED)能發現各個資安類別的新興資安事件,並有91.09%的偵測精確率,驗證ESED確實能幫助資安人員快速以及有效的應用威脅情資。
With the growth of the Internet and technology, several online services are developing rapidly, and many kinds of security threats and evolving trends are also emerging. In order to respond to various emerging security trends, many companies and organizations start to collect and analyze threat intelligence from multiple sources, in order to obtain complete information on cyber-attacks. According to the attack methods used by hackers, establish corresponding security protection measures to prevent related malicious activities is necessary.
There are diverse sources of threat intelligence, such as news, social media, and forums, where the news will publish real-time event reports after the security incident happened, using news as a source of threat intelligence can get first-hand security information to prevent possible attacks. However, there are many sources of news reports, manually browsing, collecting, and analyzing are not only time-consuming but also require a lot of resources. Therefore, it is necessary to use automated systems to conduct threat intelligence analysis. In view of this, this paper proposes an Emerging Security Event Detection System (ESED), which automatically collects security news, retrieves security event keywords, and use topic models and clustering algorithm to analyze news and detect emerging security events by two-stage clustering and similarity comparison.
The results of experiment prove that ESED can detect emerging security events in different security categories, with the detection precision rate of 91.09%, confirmed that ESED can truly help security personnel apply threat intelligence quickly and effectively.
QR Code