Design of a Classification Model for a Twitter-Based Streaming Threat Monitor
Fernando Alves, Pedro Ferreira, Alysson Bessani · 2019
Receiving timely and relevant security information is crucial to maintaining a high-security level on an IT infrastructure. This information can be extracted from Open Source Intelligence published daily by users, security companies, and hackers. In particular, Twitter has become an information hub for obtaining cutting edge information about many subjects, including cybersecurity. This work discusses the design of a classifier model for a Twitter-based threat monitor for generating a summary of the threat landscape related to a given monitored IT infrastructure. Since the classifier is a crucial element of the processing pipeline that constitutes the threat monitor, its architecture, topology and hyper-parameters must be properly selected to achieve high true positive and true negative classification rates. Our experimental work considered two architectural approaches: a single model for the whole IT infrastructure or an ensemble of models, one for each of several parts of the infrastructure. Within this scope we tested one linear (support vector machine) and one non-linear (multi-layer perceptron) modelling technique. Finally, several model design variables, hyper-parameters and learning parameters were selected by grid-search.