Artificial Intelligence and Big Data Driven IS Security Management Solution with Applications in Higher Education Organizations
2021 17th International Conference on Network and Service Management (CNSM 2021): Proceedings 2021
Vladislavs Minkevičs, Jānis Kampars

This paper presents the architecture of a modular big-data-based information system (IS) security management system (ISMS) and elaborates one of its modules - artificial intelligence driven NetFlow data analysis (NFAI) module. The ISMS is used in production at Riga Technical University and can be adapted for use in other organizations. The proposed platform is based on mostly free and open-source tools and allows to prevent or minimize the consequences of malware's activity with little impact on the employee's privacy. The presented NFAI detection module provides detection of malware activity by extracting features from NetFlow data within a 10-minute interval and feeding it into several trained classifiers. ISMS does not rely solely on NFAI module alone, it uses an ensemble of modules and algorithms to increase the accuracy of the malware detection. The presented IS security management system can be employed in real-time environment and its NFAI detection module allows to identify an infected device as soon as it starts to communicate with the botnet (a logical collection of Internet-connected devices such as computers, smartphones or IoT devices whose security have been breached and control ceded to a third party) command and control centre to obtain new commands. The presented NFAI module has been validated in the production environment and identified infected devices which were not detected by antivirus software nor by firewall or Intrusion Detection System.


Keywords
IS security, big data, malware, NetFlow, artificial intelligence
DOI
10.23919/CNSM52442.2021.9615575
Hyperlink
https://ieeexplore.ieee.org/document/9615575

Minkevičs, V., Kampars, J. Artificial Intelligence and Big Data Driven IS Security Management Solution with Applications in Higher Education Organizations. In: 2021 17th International Conference on Network and Service Management (CNSM 2021): Proceedings, Turkey, Izmir, 25-29 October, 2021. Piscataway: IEEE, 2021, pp.340-344. ISBN 978-1-6654-2457-8. e-ISBN 978-3-903176-36-2. ISSN 2165-9605. e-ISSN 2165-963X. Available from: doi:10.23919/CNSM52442.2021.9615575

Publication language
English (en)
The Scientific Library of the Riga Technical University.
E-mail: uzzinas@rtu.lv; Phone: +371 28399196