Transfer and online learning for IP maliciousness prediction in a concept drift scenario.

Saved in:
Bibliographic Details
Title: Transfer and online learning for IP maliciousness prediction in a concept drift scenario.
Authors: Escudero García, David1 (AUTHOR) descg@unileon.es, DeCastro-García, Noemí2 (AUTHOR)
Source: Wireless Networks (10220038). Dec2024, Vol. 30 Issue 9, p7423-7444. 22p.
Subjects: Data distribution, Internet protocol address, Online education, Transfer of training, Machine tools
Abstract: Determining the maliciousness of a cybersecurity incident is essential to establish effective measures against it. To process large volumes of data in an automated way, machine learning techniques are commonly applied to the problem. One of the main obstacles to apply machine learning effectively is that the data distribution is not stationary, so a model trained on old data tends to degrade as new data with a different distribution is processed. This change in the distribution of data over time is known as concept drift and affects the reports of new events, which may compromise model performance. To tackle this problem this paper evaluates the effectiveness of transfer learning techniques in reducing the impact of concept drift on the performance of models for assigning maliciousness to IPs. We compare this approach with the application of online-updated models, which are another common approach to adapt to concept drift in the data. We analyse the performance of both approaches to determine which may be more effective in this setting. [ABSTRACT FROM AUTHOR]
Copyright of Wireless Networks (10220038) is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Full text is not displayed to guests.
FullText Links:
  – Type: pdflink
Text:
  Availability: 1
Header DbId: egs
DbLabel: Engineering Source
An: 181064213
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Transfer and online learning for IP maliciousness prediction in a concept drift scenario.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Escudero+García%2C+David%22">Escudero García, David</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> descg@unileon.es</i><br /><searchLink fieldCode="AR" term="%22DeCastro-García%2C+Noemí%22">DeCastro-García, Noemí</searchLink><relatesTo>2</relatesTo> (AUTHOR)
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Wireless+Networks+%2810220038%29%22">Wireless Networks (10220038)</searchLink>. Dec2024, Vol. 30 Issue 9, p7423-7444. 22p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Data+distribution%22">Data distribution</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+protocol+address%22">Internet protocol address</searchLink><br /><searchLink fieldCode="DE" term="%22Online+education%22">Online education</searchLink><br /><searchLink fieldCode="DE" term="%22Transfer+of+training%22">Transfer of training</searchLink><br /><searchLink fieldCode="DE" term="%22Machine+tools%22">Machine tools</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Determining the maliciousness of a cybersecurity incident is essential to establish effective measures against it. To process large volumes of data in an automated way, machine learning techniques are commonly applied to the problem. One of the main obstacles to apply machine learning effectively is that the data distribution is not stationary, so a model trained on old data tends to degrade as new data with a different distribution is processed. This change in the distribution of data over time is known as concept drift and affects the reports of new events, which may compromise model performance. To tackle this problem this paper evaluates the effectiveness of transfer learning techniques in reducing the impact of concept drift on the performance of models for assigning maliciousness to IPs. We compare this approach with the application of online-updated models, which are another common approach to adapt to concept drift in the data. We analyse the performance of both approaches to determine which may be more effective in this setting. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Wireless Networks (10220038) is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=181064213
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s11276-024-03664-x
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 22
        StartPage: 7423
    Subjects:
      – SubjectFull: Data distribution
        Type: general
      – SubjectFull: Internet protocol address
        Type: general
      – SubjectFull: Online education
        Type: general
      – SubjectFull: Transfer of training
        Type: general
      – SubjectFull: Machine tools
        Type: general
    Titles:
      – TitleFull: Transfer and online learning for IP maliciousness prediction in a concept drift scenario.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Escudero García, David
      – PersonEntity:
          Name:
            NameFull: DeCastro-García, Noemí
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 12
              Text: Dec2024
              Type: published
              Y: 2024
          Identifiers:
            – Type: issn-print
              Value: 10220038
          Numbering:
            – Type: volume
              Value: 30
            – Type: issue
              Value: 9
          Titles:
            – TitleFull: Wireless Networks (10220038)
              Type: main
ResultId 1