端末の監視データから将来のサイバー損失確率を推定
A Framework to Quantify the Probability of Future Cyber Loss Events
この論文をやさしく読む
ひとことで言うと
端末ごとの監視情報から将来のサイバー損失事象の確率を予測し、それをサービスや組織の階層へ集約する方法です。端末同士が独立とは限らないことも考慮します。
何に役立つ?
組織内のリスクを確率として把握し、どの端末や業務を重視するかを検討する基礎になりえます。要旨で評価されたのは損失事象の発生予測で、金銭的損失額の予測結果ではありません。
この研究の面白いところ
端末単位の機械学習予測と、組織構造に沿った集約を結び付けています。判別能力だけでなく、予測確率の較正も評価している点が重要です。
どこまで分かった?
評価は特定の製品を使う23組織の非公開データに基づきます。平均ROC-AUC 0.90は正解率90%を意味せず、要旨には較正誤差の具体値や組織全体での集約精度は示されていません。
v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。
アブストラクトの日本語訳
サイバーセキュリティリスクの定量化は、運用データの不足や損失事象頻度(LEF)の定量化の難しさにより、依然として課題である。本論文は、LEFの推定を、端末単位のサイバー損失事象(CLE)の予測とインフラ階層での集約を組み合わせた問題に再定式化する、確率的な枠組みLoss Event Frequency Security Analyser(LEFSA)を提案する。LEFSAは運用中のサイバーセキュリティ監視データから、較正された端末単位のCLE発生確率を推定し、端末間の依存関係を考慮しながらインフラの各階層で集約する。これにより、端末、サービス、業務プロセス、組織全体という各レベルで、拡張性と説明可能性があり、運用に適用できるサイバーリスク推定の基盤を提供する。 この枠組みを、Microsoft Defender for Endpointを利用する23組織の非公開のManaged Detection & Response監視データで評価した。XGBoostが最も高い予測性能を示し、受信者動作特性曲線下面積の平均は0.90で、各評価期間を通じて較正誤差も一貫して低かった。結果は、運用中のサイバーセキュリティ監視データに将来のCLE発生に関する豊富な予測情報が含まれることを示しており、端末単位の確率モデルと階層的集約が、定量的でデータ駆動型のサイバーリスク管理の有望な基盤となることを支持する。
v1の要旨から自動生成。本文の精読・人による確認は未実施。
- 初稿
- 2026-09-18(UTC)
- 最新改訂
- 2026-09-18 · v1
- 査読・掲載
- 査読状況未確認
更新履歴
- v1 2026-09-18 この版を読む
取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。
原文の要旨
Cybersecurity risk quantification remains challenging due to limited operational data and difficulties in quantifying Loss Event Frequency (LEF). This paper introduces the Loss Event Frequency Security Analyser (LEFSA), a probabilistic framework that reformulates LEF estimation as machine-level Cyber Loss Event (CLE) prediction combined with hierarchical infrastructure-level aggregation. LEFSA estimates calibrated machine-level CLE probabilities from operational cybersecurity telemetry and aggregates them across infrastructure layers while accounting for machine-level dependencies. This provides a foundation for scalable, explainable, and operationally applicable cyber risk estimation at the level of machines, services, business processes, and the entire organization. The framework was evaluated using proprietary Managed Detection & Response telemetry from 23 organizations using Microsoft Defender for Endpoint. XGBoost achieved the strongest predictive performance, with a mean area under the receiver operating characteristic curve of 0.90 and consistently low calibration error across evaluation periods. The results demonstrate that operational cybersecurity telemetry contains substantial predictive information for future CLE occurrence, supporting probabilistic machine-level modeling and hierarchical aggregation as a promising foundation for quantitative, data-driven cyber risk management.
著者のコメント
Preprint. Accepted for publication in the Proceedings of CYBER 2026: The Eleventh International Conference on Cyber-Technologies and Cyber-Systems
arXiv ID: 2609.21717 / 要約の誤りについて