An Approach for Intelligent Behaviour-Based Threat Modelling with Explanations

被引:0
|
作者
Preetam, Sonu [1 ,2 ]
Compastie, Maxime [1 ]
Daza, Vanesa [2 ]
Siddiqui, Shuaib [1 ]
机构
[1] i2CAT Fdn, Cybersecur Dept, Barcelona, Spain
[2] Univ Pompeu Fabra, Dept Informat & Commun Technol, Barcelona, Spain
关键词
Cyber-Threat Intelligence; Behaviour Modelling; Attack Graphs; Explainability; Correlation;
D O I
10.1109/NFV-SDN59219.2023.10329587
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
To disrupt the emergence of novel threats, defenders must obtain insights into the attacker's behaviours through Tactics, Techniques, and Procedures (TTP) to establish adequate countermeasures. However, albeit detecting the usage of a subset of techniques is well documented and investigated, understanding the chaining of these techniques into a complete set of attack scenarios remains a manned process, prone to errors in complex and dynamic environments, such as software networks. In this paper, we propose a hybrid model for threat behaviour profiling. Our model exploits multimodal threat data using diverse realtime logs from virtualised environments to generate a novel dataset that maximises the explainability of a technique. Once a set of techniques is qualified, we leverage attack graphs and AI model explanations to correlate techniques usage into attack scenarios describing a complete behaviour from a threat actor. Our proposed approach is generalizable to distributed and heterogeneous environments, making it a promising method against ever-evolving threats.
引用
收藏
页码:197 / 200
页数:4
相关论文
共 50 条
  • [1] The behaviour-based approach to safety
    Sellers, G
    Eyre, P
    [J]. HAZARDS XV: THE PROCESS, ITS SAFETY AND THE ENVIRONMENT - GETTING IT RIGHT, 2000, (147): : 385 - 395
  • [2] A methodology for provably stable behaviour-based intelligent control
    Harper, CJ
    Winfield, AFT
    [J]. ROBOTICS AND AUTONOMOUS SYSTEMS, 2006, 54 (01) : 52 - 73
  • [3] Threat modelling on nuclear and radioactive materials based on intelligent approach
    Hossain, Altab
    Salahuddin, A.Z.M.
    Akbar, M.S.
    [J]. International Journal of Nuclear Energy Science and Technology, 2018, 12 (01): : 19 - 31
  • [4] Proactive threat hunting to detect persistent behaviour-based advanced adversaries
    Bhardwaj, Akashdeep
    Bharany, Salil
    Almogren, Ahmad
    Rehman, Ateeq Ur
    Hamam, Habib
    [J]. EGYPTIAN INFORMATICS JOURNAL, 2024, 27
  • [5] Embedding learning in behaviour-based architectures: a conceptual approach
    Sequeira, J
    Millan, JD
    Ribeiro, MI
    Goncalves, JGM
    [J]. JOURNAL OF INTELLIGENT MANUFACTURING, 1998, 9 (02) : 201 - 207
  • [6] Embedding learning in behaviour-based architectures: a conceptual approach
    João Sequeira
    Jose´ Del R. Milla´n
    M. Isabel Ribeiro
    João G. M. Gonc¸alves
    [J]. Journal of Intelligent Manufacturing, 1998, 9 : 201 - 207
  • [7] An Information Behaviour-Based Approach to Virtual Doctor Design
    Sin, Jaisie
    Munteanu, Cosmin
    [J]. PROCEEDINGS OF THE 21ST INTERNATIONAL CONFERENCE ON HUMAN-COMPUTER INTERACTION WITH MOBILE DEVICES AND SERVICES (MOBILEHCI'19), 2019,
  • [8] A CBR approach to behaviour-based navigation for an autonomous mobile robot
    Poncela, Alberto
    Urdiales, Cristina
    Sandoval, Francisco
    [J]. PROCEEDINGS OF THE 2007 IEEE INTERNATIONAL CONFERENCE ON ROBOTICS AND AUTOMATION, VOLS 1-10, 2007, : 3681 - +
  • [9] Behaviour-based modelling of hexapod locomotion:: linking biology and technical application
    Dürr, V
    Schmitz, J
    Cruse, H
    [J]. ARTHROPOD STRUCTURE & DEVELOPMENT, 2004, 33 (03) : 237 - 250
  • [10] Intelligent behaviour-based team UUVs cooperation and navigation in a water flow environment
    Hou, Yan
    Allen, Robert
    [J]. OCEAN ENGINEERING, 2008, 35 (3-4) : 400 - 416