CECILIA: Enhancing CSIRT Effectiveness with Transformer-Based Cyber Incident Classification
Juan Jose Delgado Sotes, Alicia Martinez Mendoza, Andres Carofilis Vasco, Eduardo Fidalgo Fernandez, Enrique Alegre Gutierrez
Abstract
This paper introduces an approach to improv ing incident response times by applying various Artificial Intelligence (AI) classification algorithms based on transformers to analyze the efficacy of these models in categorizing cyber incidents. As a first contribution, we developed a cyber incident dataset, CECILIA-10C-900, collecting cyber incident reports from six qualified web sources. The contribution of creating a dataset on cyber incident detection is remarkable due to the scarcity of such datasets. Each incident has been tagged by hand according to the cyber incident taxonomy defined by the CERT (Computer Emergency Response Team) of the National Institute of Cybersecurity (INCIBE). This dataset is highly unbalanced, so we decided to unify the four least represented classes under the label “others”, leaving a dataset with six categories (CECILIA-6C-900). With these reliable datasets, we performed a comparison of the best algorithms specifically for the cyber incident classification problem, evaluating eight different metrics on two conventional classifiers and six other transformer-based classifiers. Our study highlights the importance of having a rapid classification mechanism for CSIRTs (Computer Security Incident Response Teams) and showcases the potential of machine learning algorithms to improve cyber defense mechanisms. The findings from our analysis provide valuable insights into the strengths and limitations of different classification techniques. It can be used in future work on cyber incident response strategies- Anthology ID:
- 2024.nlpaics-1.21
- Volume:
- Proceedings of the First International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security
- Month:
- July
- Year:
- 2024
- Address:
- Lancaster, UK
- Editors:
- Ruslan Mitkov, Saad Ezzini, Tharindu Ranasinghe, Ignatius Ezeani, Nouran Khallaf, Cengiz Acarturk, Matthew Bradbury, Mo El-Haj, Paul Rayson
- Venue:
- NLPAICS
- SIG:
- Publisher:
- International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security
- Note:
- Pages:
- 186–195
- Language:
- URL:
- https://preview.aclanthology.org/fix-sig-urls/2024.nlpaics-1.21/
- DOI:
- Cite (ACL):
- Juan Jose Delgado Sotes, Alicia Martinez Mendoza, Andres Carofilis Vasco, Eduardo Fidalgo Fernandez, and Enrique Alegre Gutierrez. 2024. CECILIA: Enhancing CSIRT Effectiveness with Transformer-Based Cyber Incident Classification. In Proceedings of the First International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security, pages 186–195, Lancaster, UK. International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security.
- Cite (Informal):
- CECILIA: Enhancing CSIRT Effectiveness with Transformer-Based Cyber Incident Classification (Sotes et al., NLPAICS 2024)
- PDF:
- https://preview.aclanthology.org/fix-sig-urls/2024.nlpaics-1.21.pdf