Power Law based Cyber Defence

Copy Link
Techy graphic of a laptop

A large number of breaches are the result of misconfigured security and monitoring solutions that fail to detect and alert the system administrators to malicious activity. The problem in the case of many of breaches is twofold:

(1) the amount of data collected for detection and prevention purposes is overwhelming and cannot be processed in a timely manner and
(2) it is difficult to determine where the detection and prevention activity needs to be focused.

We have worked with industry and government organizations for more a than decade, performing security reviews and our experience showed that organizations very rarely have in place well-tuned security solutions for multiple reasons:

(1) the initial deployment failed to take into account the local context information and
(2) the network infrastructure changed over time with the majority of the organizations using new cloud-based assets, and
(3) most organizations, with exception of major financial institutions and some critical infrastructure government departments, lack an in-house capacity to deploy and fine-tune cyber security solutions and as a result, outsource the work to dedicated third party security providers that can provide some of form of cyber defence – however this defence is again, lacking the customization that is required to provide the best defence (as the organization network and assets change, the configuration of the third party managed tools stay the same). What is required is an effective method to focus the defensive efforts on key data collected from the different network and system sensors that can be used to both enhance detection and prevention as well provide a set of adaptive data features to identify anomalies without human expert intervention.

Aim  

Our proposed research will directly address the need for adaptive data features and means to focus the defensive solutions on the processes and activities that would be the source of anomalous behaviour. Thus, our approach would ensure the timely processing of data which is essential for early detection of possible breaches. At the core of our approach will be the use of rarely used power law in cyber security – Pareto’s Law and machine learning. Specifically we will use the power law to reduce the complexity of the network/system data analysis while machine learning will be used to identify deviations from the norms derived from the power law.

Objectives 

The research we propose will include the following three specific aims:

  1. investigate which adaptive data features based Pareto’s Law are best at identifying anomalous behaviour at the log and meta-data level,
  2. investigate if multi-resolution analysis can provide enhanced detection of anomalous behaviour, and
  3. explore which machine learning methods are most effective in detecting anomalies and enabling corrective actions from the network/system administrators.

We will need to address the following key questions:

  1. Which sources of information best capture the evolving nature of the organization’s infrastructure based on Pareto’s Law (log, meta-data or both)?
  2. What are the most effective features that can be extracted from network and system data based on Pareto’s Law (primary or secondary)?
  3. Which machine learning methodologies are best suited for detecting deviations in the network or system data according to Pareto’s Law?

Significance 

The proposed work will directly contribute to the network defence initiatives and makes a significant contribution to the Science and Research Priority number 4 – Cybersecurity – as outlined in the Science Council document. The research will immediately benefit a wide range of users: from government organizations, and institutions, to businesses and individuals, who lack the capacity and resources to customize their cyber defence solutions. Critically, the our proposed work will provide the organizations with a pro-active, context aware methodology that will enhance their cyber security defensive posture. In addition, the outcomes of the project will provide business opportunities for manufacturers of cyber security products to enhance the security posture of Internet facing organizations. To the research community, the project will provide both a set of tools and an extensive attacker focused framework which we believe will lead to the advancement of knowledge in the area.

Ideal Candidate 

The candidate should have a very good mathematical background and ability to rapidly prototype software that allows the practical application of the concepts and theory developed as part of the PhD. In addition, cyber security knowledge is essential for the project, particularly from a blue team perspective. Additionally, the applicants should meet the eligibility criteria for entry into a PhD program at Curtin University. 

This project is open to International and Domestic applicants. 

Scholarship  

If you are identified as the preferred candidate for this project, you may be considered for an RTP scholarship

Enquires and How to Apply 

For enquires about this opportunity contact Associate Professor Mihai Lazarescu at M.Lazarescu@curtin.edu.au

To formally apply submit an Expression of Interest to Associate Professor Mihai Lazarescu during the Central Scholarship round (July 1st – July 31st 2026) 

Copy Link