Multimodal Technologies and Interaction (Sep 2019)

Text Mining in Cybersecurity: Exploring Threats and Opportunities

  • Maaike H. T. de Boer,
  • Babette J. Bakker,
  • Erik Boertjes,
  • Mike Wilmer,
  • Stephan Raaijmakers,
  • Rick van der Kleij

DOI
https://doi.org/10.3390/mti3030062
Journal volume & issue
Vol. 3, no. 3
p. 62

Abstract

Read online

The number of cyberattacks on organizations is growing. To increase cyber resilience, organizations need to obtain foresight to anticipate cybersecurity vulnerabilities, developments, and potential threats. This paper describes a tool that combines state of the art text mining and information retrieval techniques to explore the opportunities of using these techniques in the cybersecurity domain. Our tool, the Horizon Scanner, can scrape and store data from websites, blogs and PDF articles, and search a database based on a user query, show textual entities in a graph, and provide and visualize potential trends. The aim of the Horizon Scanner is to help experts explore relevant data sources for potential threats and trends and to speed up the process of foresight. In a requirements session and user evaluation of the tool with cyber experts from the Dutch Defense Cyber Command, we explored whether the Horizon Scanner tool has the potential to fulfill its aim in the cybersecurity domain. Although the overall evaluation of the tool was not as good as expected, some aspects of the tool were found to have added value, providing us with valuable insights into how to design decision support for forecasting analysts.

Keywords