[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126136-en":3,"doc-seo-126136-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126136,687207022233,"Riley","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Application of Machine Learning on Cyber Threat Intelligence Data - Master’s Thesis","Cybersecurity is a critical concern as cyber threats increasingly endanger individuals, organizations, and governments. This thesis explores how machine learning applied to cyber threat intelligence (CTI) data can support defenses against malicious activity. The work focuses on processing CTI datasets, performing exploratory data analysis, identifying and engineering features, and training ML classifiers to predict cyber attack categories. An iterative workflow of refinement and validation aims to build a robust modeling framework for reliable category prediction.","FACULTY OF INFORMATION TECHNOLOGY AND ELECTRICAL ENGINEERING  \nAsad Hasan  \nAPPLICATION OF MACHINE LEARNING ON CYBER THREAT INTELLIGENCE DATA  \nMaster’s Thesis  \nDegree Programme in Computer Science and Engineering  \nHasan A. (2024) Application of Machine Learning on Cyber Threat Intelligence Data. University of Oulu, Degree Programme in Computer Science and Engineering, 66 p.  \nABSTRACT  \nCybersecurity stands as a paramount concern in today’s digital landscape, with the proliferation of cyber threats posing significant risks to individuals, organizations, and governments worldwide. In response to this escalating challenge, the fusion of machine learning (ML) techniques with cyber threat intelligence (CTI) data emerges as a promising approach which can help develop defense mechanisms against malicious activities. This thesis investigates the application of ML algorithms to CTI datasets for predicting the categories of cyber attacks, aiming to model CTI datasets for ML and develop a predictive model capable of discerning attack categories amidst the complex cyber threat landscape. Methodologically, the research employs a systematic approach to dataset processing and ML classifier training, encompassing feature identification, engineering, and selection, as well as iterative model refinement and validation. The envisioned outcomes include the ability to model CTI datasets to effectively predict attack categories with confidence. Through extensive data processing, exploratory data analysis, and feature engineering, this research contributes to the advancement of cybersecurity by providing a robust framework for modelling CTI data and accurately predicting cyber attack categories.  \nKeywords: Cybersecurity, Cyber threats, Machine learning (ML), Cyber threat intelligence (CTI) data, Defense mechanisms, Predicting the categories of cyber attacks, Dataset processing, ML classifier training, Feature engineering, Exploratory data analysis, Predict attack categories, Cyber threat landscape  \nTABLE OF CONTENTS  \nABSTRACT  \nTABLE OF CONTENTS  \nFOREWORD  \nLIST OF ABBREVIATIONS AND SYMBOLS 1. INTRODUCTION....................................................................................... 7  \n1.1. Research Objectives ............................................................................ 8  \n1.2. Structure of Thesis .............................................................................. 8  \n2. LITERATURE REVIEW ............................................................................. 9  \n2.1. Methodological Insights from ’Cloudy with a Chance of Breach: Forecasting Cyber Security Incidents’.................................................. 11  \n2.2. Methodological Insights from ’A Framework for Fast and Efficient Cyber Security Network Intrusion Detection Using Apache Spark’........ 12  \n3. RESEARCH DESIGN................................................................................. 14  \n3.1. Tools and Technologies ....................................................................... 14  \n3.2. Datasets ............................................................................................. 17  \n3.3. Data Pre-Processing ............................................................................ 18  \n3.3.1. Handling Null Values .............................................................. 19  \n3.4. Feature Engineering ............................................................................ 21  \n3.4.1. Concatenating Data for Missing Target Class ............................ 22  \n3.4.2. Feature Engineering: Textual to Numeric .................................. 23  \n3.4.3. Handling IP Addresses ............................................................ 24  \n3.4.4. Handling Textual Columns with High Categorical Count ........... 24  \n3.4.5. Engineering Features Using Bag of Words ................................ 25  \n3.4.6. Engineering Features Using One-Hot Encoding......................... 25  \n3.4.7. Summary","cbCairkZEuU4HW1M","https://ap.wps.com/l/cbCairkZEuU4HW1M","pdf",1970095,4,1,66,"English","en",105,"# Abstract\n# Table of Contents\n# Foreword\n# List of Abbreviations and Symbols\n# 1. Introduction\n## 1.1. Research Objectives\n## 1.2. Structure of Thesis\n# 2. Literature Review\n## 2.1. Methodological Insights from ’Cloudy with a Chance of Breach: Forecasting Cyber Security Incidents’\n## 2.2. Methodological Insights from ’A Framework for Fast and Efficient Cyber Security Network Intrusion Detection Using Apache Spark’\n# 3. Research Design\n## 3.1. Tools and Technologies\n## 3.2. Datasets\n## 3.3. Data Pre-Processing\n## 3.3.1. Handling Null Values\n## 3.4. Feature Engineering\n## 3.5. Data Visualization\n## 3.6. Machine Learning\n# 4. Implementation\n## 4.1. Random Forest Classifier\n## 4.2. Performance Metrics\n## 4.3. Other Evaluation Techniques to Consider\n## 4.4. Constructing the Model\n## 4.5. Evaluating Performance\n# 5. Results\n## 5.1. Hyperparameter Tuning of Random Forest\n## 5.2. Best Performing Model\n# 6. Discussion\n## 6.1. Modelling CTI Datasets for Machine Learning\n## 6.2. Random Forest Classifier Implemntation","[{\"question\":\"What is the main goal of the thesis?\",\"answer\":\"To apply machine learning to cyber threat intelligence data in order to predict categories of cyber attacks.\"},{\"question\":\"How does the thesis prepare the CTI datasets for modeling?\",\"answer\":\"It uses systematic dataset processing including exploratory data analysis, null-value handling, and multiple forms of feature engineering.\"},{\"question\":\"Which machine learning approach is used and how is its performance evaluated?\",\"answer\":\"A Random Forest classifier is trained, tuned, and evaluated using metrics, hyperparameter optimization, and validation strategies such as cross validation and stratified sampling.\"}]","Application of Machine Learning on Cyber Threat Intelligence Data - Master’s Thesis | PDF",1785903347,166,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"application-of-machine-learning-on-cyber-threat-intelligence-data-masters-thesis","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":20},"https://docshare.wps.com/document/application-of-machine-learning-on-cyber-threat-intelligence-data-masters-thesis/126136/",{"url":53,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the main goal of the thesis?","Question",{"text":76,"@type":77},"To apply machine learning to cyber threat intelligence data in order to predict categories of cyber attacks.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the thesis prepare the CTI datasets for modeling?",{"text":81,"@type":77},"It uses systematic dataset processing including exploratory data analysis, null-value handling, and multiple forms of feature engineering.",{"name":83,"@type":74,"acceptedAnswer":84},"Which machine learning approach is used and how is its performance evaluated?",{"text":85,"@type":77},"A Random Forest classifier is trained, tuned, and evaluated using metrics, hyperparameter optimization, and validation strategies such as cross validation and stratified sampling.","https://schema.org",{"og:url":53,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]