We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Graphing Website Relationships for Risk Prediction: Identifying Derived Threats to Users Based on Known Indicators

Abstract: The hypothesis for the study was that the relationship based on referrer links and the number of hops to a malicious site could indicate the risk to another website. We chose Receiver Operating Characteristics (ROC) analysis as the method of comparing true positive and false positive rates for captured web traffic to test the predictive capabilities of our model. Known threat indicators were used as designators, and the Neo4j graph database was leveraged to map the relationships between other websites based on referring links. Using the referring traffic, we mapped user visits across websites with a known relationship to track the rate at which users progressed from a non-malicious website to a known threat. The results were grouped by the hop distance from the known threat to calculate the predictive rate. The results of the model produced true positive rates between 58.59% and 63.45% and false positive rates between 7.42% to 37.50%, respectively. The true and false positive rates suggest an improved performance based on the closer proximity from the known threat, while an increased referring distance from the threat resulted in higher rates of false positives.
Comments: 10 pages, 3 figures, 3 tables
Subjects: Cryptography and Security (cs.CR); Databases (cs.DB); Networking and Internet Architecture (cs.NI)
ACM classes: C.2.4; H.2.4; E.2; C.2.1
DOI: 10.1007/978-3-030-63089-8
Cite as: arXiv:2003.00971 [cs.CR]
  (or arXiv:2003.00971v1 [cs.CR] for this version)

Submission history

From: Philip Kulp [view email]
[v1] Mon, 2 Mar 2020 15:41:48 GMT (431kb)

Link back to: arXiv, form interface, contact.