Predictive Blacklisting as an Implicit Recommendation System

16
Predictive Blacklisting as an Implicit Recommendation System Authors: Fabio Soldo, Anh Le, Athina Markopoulou IEEE INFOCOM 2010 Reporter: Jing Chiu Advisor: Yuh-Jye Lee Email: [email protected] 111/06/2 1 1 Data Mining & Machine Learning Lab

description

Predictive Blacklisting as an Implicit Recommendation System. Authors: Fabio Soldo, Anh Le, Athina Markopoulou IEEE INFOCOM 2010 Reporter: Jing Chiu Advisor: Yuh-Jye Lee Email: [email protected]. Outlines. Introduction Blacklists Recommendation System Related Works LWOL GWOL - PowerPoint PPT Presentation

Transcript of Predictive Blacklisting as an Implicit Recommendation System

Page 1: Predictive Blacklisting as an Implicit Recommendation System

Predictive Blacklisting as an Implicit Recommendation System

Authors: Fabio Soldo, Anh Le, Athina MarkopoulouIEEE INFOCOM 2010Reporter: Jing ChiuAdvisor: Yuh-Jye LeeEmail: [email protected]

112/04/22 1Data Mining & Machine Learning Lab

Page 2: Predictive Blacklisting as an Implicit Recommendation System

Outlines• Introduction

▫ Blacklists▫ Recommendation System

• Related Works▫ LWOL▫ GWOL▫ HPB▫ Room for improvement

• DSHIELD Dataset Observation• Model Overview

▫ Time Series EWMA

▫ Neighborhood Model kNN CA

• Evaluation• Conclusions

112/04/22 2Data Mining & Machine Learning Lab

Page 3: Predictive Blacklisting as an Implicit Recommendation System

•Blacklists•Recommendation System

Introduction

112/04/22 Data Mining & Machine Learning Lab 3

Page 4: Predictive Blacklisting as an Implicit Recommendation System

•Local Worst Offender List(LWOL)•Global Worst Offender List(GWOL)•Highly Predictive Blacklisting(HPB)

▫J. Zhang, P. Porras, and J. Ullrich, “Highly predictive blacklisting,” in Proc. of USENIX Security ’08 (Best Paper award), San Jose, CA, USA, Jul. 2008, pp. 107–122.

Related Works

112/04/22 Data Mining & Machine Learning Lab 4

Page 5: Predictive Blacklisting as an Implicit Recommendation System

Room for improvement

112/04/22 Data Mining & Machine Learning Lab 5

Page 6: Predictive Blacklisting as an Implicit Recommendation System

DSHIELD Dataset Observation

112/04/22 Data Mining & Machine Learning Lab 6

Page 7: Predictive Blacklisting as an Implicit Recommendation System

DSHIELD Dataset Observation(cont.)

112/04/22 Data Mining & Machine Learning Lab 7

Page 8: Predictive Blacklisting as an Implicit Recommendation System

DSHIELD Dataset Observation(cont.)

112/04/22 Data Mining & Machine Learning Lab 8

Page 9: Predictive Blacklisting as an Implicit Recommendation System

•Time Series for Attack Prediction▫Exponential Weighted Moving Average(EWMA)

•Neighborhood Model▫Victim Neighborhood (kNN)

k-nearest neighbor Pearson correlation as similarity metric

▫Joint Attacker-Victim Neighborhood (CA) cross-associations Fully automatic clustering algorithm that finds

row and column groups of sparce binary matrices

Model Overview

112/04/22 Data Mining & Machine Learning Lab 9

Page 10: Predictive Blacklisting as an Implicit Recommendation System

•Local approaches•Global (neighborhood) approaches•Proposed combined method•Robustness

Evaluations

112/04/22 Data Mining & Machine Learning Lab 10

Page 11: Predictive Blacklisting as an Implicit Recommendation System

Evaluations (cont.)

112/04/22 Data Mining & Machine Learning Lab 11

Page 12: Predictive Blacklisting as an Implicit Recommendation System

Evaluations (cont.)

112/04/22 Data Mining & Machine Learning Lab 12

Page 13: Predictive Blacklisting as an Implicit Recommendation System

Evaluations (cont.)

112/04/22 Data Mining & Machine Learning Lab 13

Page 14: Predictive Blacklisting as an Implicit Recommendation System

Evaluations (cont.)

112/04/22 Data Mining & Machine Learning Lab 14

Page 15: Predictive Blacklisting as an Implicit Recommendation System

•Frame the problem as an implicit recommendation system

•Analyze a real dataset of 1-month logs from Dshield.rg

•Shows that even larger improvement can be obtained

•Give a methodological development with improvement over state-of-the-art.

Conclusions

112/04/22 Data Mining & Machine Learning Lab 15

Page 16: Predictive Blacklisting as an Implicit Recommendation System

•Questions?

Thanks for your attention

112/04/22 Data Mining & Machine Learning Lab 16