In this study, we aimed to identify spatial clusters of countries with high rates of cyber attacks directed at other countries. The cyber attack dataset was obtained from Canadian Institute for Cybersecurity , with over 110,000 Uniform Resource Locators (URLs), which were classified into one of 5 categories: benign, phishing, malware, spam, or defacement. The disease surveillance software SaTScanTM was used to perform a spatial analysis of the country of origin for each cyber attack. It allowed the identification of spatial and space-time clusters of locations with unusually high counts or rates of cyber attacks. Number of internet users per country obtained from the 2016 CIAWorld Factbook was used as the population baseline for computing rates and Poisson analysis in SaTScanTM. The clusters were tested for significance with a Monte Carlo study within SaTScanTM, where any cluster with p < 0.05 was designated as a significant cyber attack cluster. Results using the rate of the different types of malicious URL cyber attacks are presented in this paper. This novel approach of studying cyber attacks from a spatial perspective provides an invaluable relative risk assessment for each type of cyber attack that originated from a particular country.
Files and links (1)
pdf
The spatial analysis of the malicious Uniform Resource Locators (URLs)2.46 MBDownloadView
Published (Version of record)Article pdfCC BY V4.0, Open Access
Related links
Details
Title
The spatial analysis of the malicious Uniform Resource Locators (URLs)
Publication Details
Information, Vol.12(1), 2
Resource Type
Journal article
Publisher
Multidisciplinary Digital Publishing Institute (MDPI AG); Switzerland