English

Evidential Cyber Threat Hunting

Cryptography and Security 2021-04-22 v1 Artificial Intelligence

Abstract

A formal cyber reasoning framework for automating the threat hunting process is described. The new cyber reasoning methodology introduces an operational semantics that operates over three subspaces -- knowledge, hypothesis, and action -- to enable human-machine co-creation of threat hypotheses and protective recommendations. An implementation of this framework shows that the approach is practical and can be used to generalize evidence-based multi-criteria threat investigations.

Keywords

Cite

@article{arxiv.2104.10319,
  title  = {Evidential Cyber Threat Hunting},
  author = {Frederico Araujo and Dhilung Kirat and Xiaokui Shu and Teryl Taylor and Jiyong Jang},
  journal= {arXiv preprint arXiv:2104.10319},
  year   = {2021}
}

Comments

5 pages, SDM AI4CS 2021

R2 v1 2026-06-24T01:23:18.237Z