Improving Municipal Cyber Resiliency with a Predictive Model to Strategically Time Phishing Tests
Open AccessMunicipalities are one of the most targeted sectors for cybercriminals. They are vulnerable attack targets because they store personally identifiable information about residents. Cities often have the least number of resources to both prevent cyberattacks and recover from their destructive consequences. Reducing city vulnerability to phishing emails - one of the most common ransomware infection vectors - protects cities against attacks that could cost millions and place lives at risk. Despite receiving cybersecurity awareness training, municipal employees remain susceptible to phishing emails. Although humans are a critical line of defense needed to prevent successful phishing attacks, they should not the be sole line of defense. This research introduces the novel approach of using machine learning to strategically time municipal phishing test campaigns. Historic data consisting of demographic information, past phishing test results and inbound malware-containing email activity reports were repurposed to develop four predictive models utilizing feature engineering techniques. Collectively, the four models form the Phishing Test Campaign Schedule. The models were trained on the J48 decision tree, Naïve Bayes, k-Nearest Neighbor, Multilayer Perceptron, Random Forest, and Support Vector Machine algorithms. After cross-validation, the algorithms were evaluated using accuracy, precision, recall, and F-Measure. The following results present the algorithms that performed best for each model: Naïve Bayes on the Failures model; Random Forest on the Reporting model; J48 decision tree on the Monthly Malicious Emails model; and Random Forest on the Hourly Malicious Emails model.
- All rights reserved
Notice to Authors
If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.