The Role of Machine Learning in Cybersecurity
arXiv:2206.09707 · doi:10.1145/3545574
Abstract
Machine Learning (ML) represents a pivotal technology for current and future information systems, and many domains already leverage the capabilities of ML. However, deployment of ML in cybersecurity is still at an early stage, revealing a significant discrepancy between research and practice. Such discrepancy has its root cause in the current state-of-the-art, which does not allow to identify the role of ML in cybersecurity. The full potential of ML will never be unleashed unless its pros and cons are understood by a broad audience. This paper is the first attempt to provide a holistic understanding of the role of ML in the entire cybersecurity domain -- to any potential reader with an interest in this topic. We highlight the advantages of ML with respect to human-driven detection methods, as well as the additional tasks that can be addressed by ML in cybersecurity. Moreover, we elucidate various intrinsic problems affecting real ML deployments in cybersecurity. Finally, we present how various stakeholders can contribute to future developments of ML in cybersecurity, which is essential for further progress in this field. Our contributions are complemented with two real case studies describing industrial applications of ML as defense against cyber-threats.
References in corpus (5)
- Explainable Artificial Intelligence: Understanding, Visualizing and Interpreting Deep Learning Models
- A Survey of Network-based Intrusion Detection Data Sets
- Defensive Distillation is Not Robust to Adversarial Examples
- The Cross-evaluation of Machine Learning-based Network Intrusion Detection Systems
- SOREL-20M: A Large Scale Benchmark Dataset for Malicious PE Detection
Cited by in corpus (8)
- Generalizing intrusion detection for heterogeneous networks: A stacked-unsupervised federated learning approach
- Network Intrusion Datasets: A Survey, Limitations, and Recommendations
- Multi-SpacePhish: Extending the Evasion-space of Adversarial Attacks against Phishing Website Detectors using Machine Learning
- DomURLs_BERT: Pre-trained BERT-based Model for Malicious Domains and URLs Detection and Classification
- A Systematic Literature Review of Cyber Security Monitoring in Maritime
- Feature Attribution in 5G Intrusion Detection: A Statistical vs. Logic-Based Comparison
- Defending Network Intrusion Detection Systems Based on Graph Neural Networks Against Structural Adversarial Attacks
- Reliable LLM-Powered Decision Engines for Large-Scale Supply Chain Operations: Architecture, Safety, and Performance Guarantees