An Approach for Intelligent Behaviour-Based Threat Modelling with Explanations

被引:0
|
作者
Preetam, Sonu [1 ,2 ]
Compastie, Maxime [1 ]
Daza, Vanesa [2 ]
Siddiqui, Shuaib [1 ]
机构
[1] i2CAT Fdn, Cybersecur Dept, Barcelona, Spain
[2] Univ Pompeu Fabra, Dept Informat & Commun Technol, Barcelona, Spain
关键词
Cyber-Threat Intelligence; Behaviour Modelling; Attack Graphs; Explainability; Correlation;
D O I
10.1109/NFV-SDN59219.2023.10329587
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
To disrupt the emergence of novel threats, defenders must obtain insights into the attacker's behaviours through Tactics, Techniques, and Procedures (TTP) to establish adequate countermeasures. However, albeit detecting the usage of a subset of techniques is well documented and investigated, understanding the chaining of these techniques into a complete set of attack scenarios remains a manned process, prone to errors in complex and dynamic environments, such as software networks. In this paper, we propose a hybrid model for threat behaviour profiling. Our model exploits multimodal threat data using diverse realtime logs from virtualised environments to generate a novel dataset that maximises the explainability of a technique. Once a set of techniques is qualified, we leverage attack graphs and AI model explanations to correlate techniques usage into attack scenarios describing a complete behaviour from a threat actor. Our proposed approach is generalizable to distributed and heterogeneous environments, making it a promising method against ever-evolving threats.
引用
收藏
页码:197 / 200
页数:4
相关论文
共 50 条
  • [31] A behaviour-based design approach to earthquake-induced torsion in ductile buildings
    Paulay, T
    [J]. SEISMIC DESIGN METHODOLOGIES FOR THE NEXT GENERATION OF CODES, 1997, : 289 - 297
  • [32] A behaviour-based approach to food refusal in children with autism and pervasive developmental disorder
    Ogata, B
    Trahms, C
    Lucas, B
    Schwartz, I
    [J]. JOURNAL OF INTELLECTUAL DISABILITY RESEARCH, 2000, 44 : 414 - 415
  • [33] Elasticity of demand and behaviour-based price discrimination
    Esteves, Rosa-Branca
    Reggiani, Carlo
    [J]. INTERNATIONAL JOURNAL OF INDUSTRIAL ORGANIZATION, 2014, 32 : 46 - 56
  • [34] A behaviour-based blackboard architecture for mobile robots
    Van Brussel, H
    Moreas, R
    Zaatri, A
    Nuttin, M
    [J]. IECON '98 - PROCEEDINGS OF THE 24TH ANNUAL CONFERENCE OF THE IEEE INDUSTRIAL ELECTRONICS SOCIETY, VOLS 1-4, 1998, : 2162 - 2167
  • [35] Information provision and behaviour-based price discrimination
    De Nijs, Romain
    [J]. INFORMATION ECONOMICS AND POLICY, 2013, 25 (01) : 32 - 40
  • [36] Rethinking performance management: a behaviour-based perspective
    Moustaghfir, Karim
    Schiuma, Giovanni
    Carlucci, Daniela
    [J]. INTERNATIONAL JOURNAL OF INNOVATION AND LEARNING, 2016, 20 (02) : 169 - 184
  • [37] Bio-inspired behaviour-based control
    Siddique, Nazmul H.
    Amavasai, Balasundram P.
    [J]. ARTIFICIAL INTELLIGENCE REVIEW, 2007, 27 (2-3) : 131 - 147
  • [38] Behaviour-based approach for skill acquisition during assembly operations, starting from scratch
    Corona-Castuera, J.
    Lopez-Juarez, I.
    [J]. ROBOTICA, 2006, 24 : 657 - 671
  • [39] Behaviour-Based Object Classifier for Surveillance Videos
    Arguedas, Virginia Fernandez
    Chandramouli, Krishna
    Izquierdo, Ebroul
    [J]. ETERNAL SYSTEMS, 2012, 255 : 116 - 124
  • [40] A behaviour-based Kernel architecture for robot control
    Sequeira, J
    Ribeiro, MI
    [J]. ROBOT CONTROL 1997, VOLS 1 AND 2, 1998, : 787 - 792