arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.21717cs.CRstat.AP

量化未来网络损失事件概率的框架

A Framework to Quantify the Probability of Future Cyber Loss Events

Siem Peters, Martin Eian

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出LEFSA框架,利用机器级概率预测与分层聚合,从运营遥测数据量化未来网络损失事件概率,经23个组织数据验证,XGBoost平均AUC达0.90,为数据驱动的网络风险管理奠定基础。

中文摘要 AI 辅助

由于运营数据有限以及损失事件频率(LEF)量化困难,网络安全风险量化仍具挑战性。本文介绍了损失事件频率安全分析器(LEFSA),一个概率框架,将LEF估计重新表述为机器级网络损失事件(CLE)预测与分层基础设施级聚合的结合。LEFSA从运营网络安全遥测数据中估计校准的机器级CLE概率,并在考虑机器级依赖性的同时,跨基础设施层进行聚合。这为在机器、服务、业务流程及整个组织层面进行可扩展、可解释且可操作应用的网络风险估计奠定了基础。该框架使用来自23个组织的专有托管检测与响应遥测数据(采用Microsoft Defender for Endpoint)进行评估。XGBoost取得了最强的预测性能,平均接收者操作特征曲线下面积为0.90,且在各评估期间校准误差持续较低。结果表明,运营网络安全遥测数据包含对未来CLE发生的实质性预测信息,支持概率机器级建模和分层聚合作为定量、数据驱动的网络风险管理的有前景基础。

英文摘要

Cybersecurity risk quantification remains challenging due to limited operational data and difficulties in quantifying Loss Event Frequency (LEF). This paper introduces the Loss Event Frequency Security Analyser (LEFSA), a probabilistic framework that reformulates LEF estimation as machine-level Cyber Loss Event (CLE) prediction combined with hierarchical infrastructure-level aggregation. LEFSA estimates calibrated machine-level CLE probabilities from operational cybersecurity telemetry and aggregates them across infrastructure layers while accounting for machine-level dependencies. This provides a foundation for scalable, explainable, and operationally applicable cyber risk estimation at the level of machines, services, business processes, and the entire organization. The framework was evaluated using proprietary Managed Detection & Response telemetry from 23 organizations using Microsoft Defender for Endpoint. XGBoost achieved the strongest predictive performance, with a mean area under the receiver operating characteristic curve of 0.90 and consistently low calibration error across evaluation periods. The results demonstrate that operational cybersecurity telemetry contains substantial predictive information for future CLE occurrence, supporting probabilistic machine-level modeling and hierarchical aggregation as a promising foundation for quantitative, data-driven cyber risk management.

发表机构

  • Mnemonic

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑