Sowinski-Mydlarz, Viktor (2022) Hybrid framework for threat intelligence in digital banking combining semantic technologies with machine learning. Doctoral thesis, London Metropolitan University.
The area of this research is cybersecurity addressing the hackers and fraudsters constant attempts to find new vulnerabilities and security gaps for intrusions and extortions, especially in banking which offers opportunities for substantial financial gain through cyber-attacks. There were 42 cyber threats (relevant to banking) identified in this work, belonging to malware, man-in-the-middle, phishing, pharming, and botnet categories.
The main problems with this area of the research are the loopholes in the banking security policies. Banks often use fragmented security procedures, which do not cover all possible security threats and attack vectors. The organizations lack consistent, cohesive, and established methodology to analyse the threats. There are not many existing banking ontologies and even less of them model the whole infrastructure under the duress of threats. Mostly these models are concerned with standards and legal regulations.
To address these issues a framework for threat intelligence in digital banking has been developed. Integration of the semantic technologies approach with Machine Leaming has been proposed as the hybrid framework combining both technologies' benefits. This framework utilizes multi-layered architecture on four levels - ontological, logical level, analytical level, and operational level. Logical analysis of the ontology of digital security in banking aids identifying the possible entry points for illegal access. The theoretical analysis was validated by verifying the framework and Machine Leaming algorithms. Intelligence Graphs (original term) which are adding the actions to knowledge graphs to form workflows, are the starting point of the horizontal integration. Intelligence Graphs were a base for validation of the framework through simulated execution of the scenarios specified in them.
The overall result and outcome of the proposed techniques is the framework designed using matrix approach, which combines vertical layering of the conceptual architecture with horizontal integration of the software implementation using cloud technologies. It was implemented as cloud application with three cornerstones: parametrization of the machine learning engines, containerization of the software components and orchestration of the cloud services. Combining multiple technologies to provide flexibility in the implementation of data services established horizontal integration.
Analytic engines deployment through containerization was also introduced. Containerized cloud services were orchestrated in workflows for running AI on demand. The model was validated using operation workflows, namely 12 scenarios of banking "journeys" under the duress of various threats. The framework is logically sound, and its implementation provided support for controlling theexecution of transactions under threats. It also provided interoperability with any Semantic Web ontology; it is generic and has been adapted to other projects. The platform combines fully automated, batch and interactive execution of the relevant tasks - data ingestion, transaction initiation, threat detection, classification, and identification, countermeasures execution, etc. The code was parameterized as opposed to hardcoded and configuration of the containerized services can be generated based on the explicitly represented meta-data about the methods used. The main restrictions were the need to manually model the infrastructure and strict specifications for successful integration.
![]() |
View Item |
Lists
Lists