Evidential Cyber Threat Hunting
Cryptography and Security
2021-04-22 v1 Artificial Intelligence
Abstract
A formal cyber reasoning framework for automating the threat hunting process is described. The new cyber reasoning methodology introduces an operational semantics that operates over three subspaces -- knowledge, hypothesis, and action -- to enable human-machine co-creation of threat hypotheses and protective recommendations. An implementation of this framework shows that the approach is practical and can be used to generalize evidence-based multi-criteria threat investigations.
Cite
@article{arxiv.2104.10319,
title = {Evidential Cyber Threat Hunting},
author = {Frederico Araujo and Dhilung Kirat and Xiaokui Shu and Teryl Taylor and Jiyong Jang},
journal= {arXiv preprint arXiv:2104.10319},
year = {2021}
}
Comments
5 pages, SDM AI4CS 2021