错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Vulnerability Analysis of Critical Resources Using Machine Learning

  • Subbaraj Karthika

摘要

Lack of cyber awareness among working professionals, especially in the IT field, has resulted in negative actors taking advantage of poorly built/configured critical resources, thereby directly or indirectly affecting the general public. As the emphasis on privacy and digital security rises, it becomes vital for service providers to ensure that their services are in fact secure for their clients to use. Although emphasis on cyber awareness is at an all-time high, it is still an enigma how people fall prey to age-old attack techniques like simple password brute forcing using wordlists that are over 10 years old. To clearly understand the crux of this problem, this study aims to provide a factual representation of the state of affairs with respect to the significance given to cybersecurity by present-day developers, by performing cyber keyword identification and frequency detection using summarization models on reports generated by proprietary vulnerability scanning software. These reports are generated by inputting a list of public facing websites, classified into three different categories, namely educational institutions, e-commerce, and healthcare, to the vulnerability scanning software. The output for each of these categories is then aggregated to become a clean data source. Followed by this, a document feature matrix that depicts the categories as columns and unique keywords as rows using TF-IDF and Bag of Words models is produced to compare the occurrence of a vulnerability among the mentioned categories. This analysis is finally presented as a report along with infographics depicting the scalar statistics. The occurrence of common vulnerabilities (e.g., OWASP Top 10) in such websites and the high exploitation potential of such vulnerabilities are a direct reflection of the lack of cyber awareness among developers and IT infrastructure professionals.