Research Article

An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks

Volume: 7 Number: 2 August 31, 2024
EN

An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks

Abstract

In recent years, there has been a noticeable trend toward targeted threats to information security, where companies are now leveraging vulnerabilities and risks associated with widely used services in order to generate financial gain. Additionally, they implement numerous precautions and consistently carry out their tasks. One item that requires precautionary measures is the network devices utilized. Network devices in computer networks possess the capability to log events. These logs enable the identification of security events on the network and facilitate the implementation of precautionary measures. Various security measures can be implemented to handle such data. One of these measures is Security Information and Event Management (SIEM). It is a system that gathers and analyzes data from networks and security devices. SIEM is a technique employed to consolidate critical information within a cohesive structure. It allows for the correlation of events from different security devices, thereby improving the monitoring capabilities of cybersecurity operations centers. This study extensively covers the critical infrastructure-SIEM relationship, current studies, critical infrastructure, cyber security policies, and SIEM. Our system design was developed using the UNSW_NB15 dataset, a widely recognized dataset in cybersecurity due to its comprehensive and realistic representation of cyber threats. This dataset consists of data obtained from network traffic, various attack activities, and real-life modern normal scenarios, making it particularly relevant to our study. With the studies, a total of 10 different categories were analyzed, with the category consisting of nine types of attacks, namely Analysis, Backdoor, DoS, Exploits, Fuzzers, Generic, Reconnaissance, Shellcode, and Worms and Normal activities. The study is divided into two as the basic structure. The first step was carried out on Google Collaboratory, and then some experimental studies were carried out in Weka. Classifications were made using several methods, including Logistic Regression (LR), Extra Trees (XT), Support Vector Machines (SVM), Random Forest (RF), and Decision Trees (DT). These methods were chosen for their proven effectiveness in similar studies. In the application developed with Google Colabratory, we achieved 98.62% in Random Forest, 99.10% in Decision Trees, 98.87% in Logistic Regression, 95.13% success in Extra Trees and 99.12% success in Support Vector Machines. As a result of the studies and experiments carried out in Weka, we achieved 92.05% in Random Forest, 100% in Decision Trees, 100% in k-Nearest Neighbours, 100% in J48, 99.19% in Naive-Bayes and 99.35% in BayesNet achievements.

Keywords

Critical infrastructures, Cyber security, Information security, Log analysis

References

  1. [1] Y. Alaca, Yapay ba˘gıs¸ıklık sistemleri ile bilgi g¨uvenli˘gi ve olay y¨onetimi gelis¸tirilmesi, M. Sc. Thesis, Karab¨uk University, 2018.
  2. [2] E. Yüksel, Experimenting, threat detection and SIEM integration with custom created honeypots, M.Sc. Thesis, Ankara Yıldırım Beyazıt University, 2019.
  3. [3] S. İşgüzar, Siber aylaklık davranışlarının bir kamu kurumu özelinde incelenmesi: log analizine dayalı bir çalışma, M. Sc. Thesis, Fırat University, 2020.
  4. [4] F. Akgiş, Anomali tespiti ic¸in log analizi, M. Sc. Thesis, ˙Istanbul University-Cerrahpas¸a, 2021.
  5. [5] R. Daş, M. Z. Gündüz, Analysis of cyber-attacks in IoT-based critical infrastructures, Int. J. Inf. Sec. Sci., 8(4) (2020), 122-133.
  6. [6] D. Gökçeoğlu, Güvenlik bilgileri ve olay yönetimi (SIEM)/Log korelasyon kurallarının yazılması, Ph. D. Thesis, Fırat University, 2021.
  7. [7] H. N. Yerlikaya, Log analysis of a large scale network by using Elastic Stack, M. Sc. Thesis, Bahc¸es¸ehir University, 2020.
  8. [8] S. Yenal, N. Akdemir, Uluslararası ilişkilerde yeni bir kuvvet çarpani: siber savaşlar üzerine bir vaka analizi, Cankiri Karatekin Univ. J. Inst. Soc. Sci., 11(1) (2020), 414-450.
  9. [9] S. Moualla, K. Khorzom, A. Jafar, Improving the performance of machine learning-based network intrusion detection systems on the UNSW-NB15 dataset, Comput. Intell. Neurosci. , 1 (2021), 5557577.
  10. [10] Z. Zoghi, G. Serpen, G., UNSW-NB15 computer security dataset: Analysis through visualization, Secur. Priv. , 7(1) (2024), e331.
APA
Gürtürk, U., & Gürkaş Aydın, Z. (2024). An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks. Journal of Mathematical Sciences and Modelling, 7(2), 60-74. https://doi.org/10.33187/jmsm.1484997
AMA
1.Gürtürk U, Gürkaş Aydın Z. An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks. Journal of Mathematical Sciences and Modelling. 2024;7(2):60-74. doi:10.33187/jmsm.1484997
Chicago
Gürtürk, Uğur, and Zeynep Gürkaş Aydın. 2024. “An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks”. Journal of Mathematical Sciences and Modelling 7 (2): 60-74. https://doi.org/10.33187/jmsm.1484997.
EndNote
Gürtürk U, Gürkaş Aydın Z (August 1, 2024) An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks. Journal of Mathematical Sciences and Modelling 7 2 60–74.
IEEE
[1]U. Gürtürk and Z. Gürkaş Aydın, “An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks”, Journal of Mathematical Sciences and Modelling, vol. 7, no. 2, pp. 60–74, Aug. 2024, doi: 10.33187/jmsm.1484997.
ISNAD
Gürtürk, Uğur - Gürkaş Aydın, Zeynep. “An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks”. Journal of Mathematical Sciences and Modelling 7/2 (August 1, 2024): 60-74. https://doi.org/10.33187/jmsm.1484997.
JAMA
1.Gürtürk U, Gürkaş Aydın Z. An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks. Journal of Mathematical Sciences and Modelling. 2024;7:60–74.
MLA
Gürtürk, Uğur, and Zeynep Gürkaş Aydın. “An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks”. Journal of Mathematical Sciences and Modelling, vol. 7, no. 2, Aug. 2024, pp. 60-74, doi:10.33187/jmsm.1484997.
Vancouver
1.Uğur Gürtürk, Zeynep Gürkaş Aydın. An Incident Management System Design to Protect Critical Infrastructures from Cyber Attacks. Journal of Mathematical Sciences and Modelling. 2024 Aug. 1;7(2):60-74. doi:10.33187/jmsm.1484997