首页> 外文会议>ASE International Conference on Cyber Security >Extending Case-Based Reasoning to Network Alert Reporting
【24h】

Extending Case-Based Reasoning to Network Alert Reporting

机译:扩展基于案例的推理到网络警报报告

获取原文

摘要

A substantial amount of cyber security analyst time is spent handling well-known and naïve threats and policy violations on the local network. This includes both the time spent actually identifying and analyzing the activity as well as generating and filing reports associated with the activity. With increasing concern over advanced persistent threats, there is an interest in the development of techniques to automatically handle well-known threats and policy violations. We propose extensions to existing case-based reasoning approaches to support the unique requirements of cyber security report generation. Specifically, we consider the fact that we are reporting on hostile actors that will attempt to game the system or manipulate the system to actually aid the actors in obfuscating their activity. In this paper, we describe the need for automated reporting, the applicability of case-based reasoning, our proposed extension to the standard case-based reasoning system model, and provide examples of the modified case-based reasoning system as applied to example cyber security scenarios.
机译:大量的网络安全分析师时间用于处理当地网络上的众所周知和天真的威胁和政策违规行为。这包括实际识别和分析活动的时间以及与活动相关联的报告的时间。随着对先进持续威胁的不断担忧,有兴趣自动处理知名威胁和政策违规的技术的发展。我们向现有的基于案例的推理方法提出了扩展,以支持网络安全报告生成的独特要求。具体而言,我们认为我们正在报告敌对行为者,这些演员将尝试游戏系统或操纵系统,以实际帮助演员在混淆他们的活动时。在本文中,我们描述了自动报告的需求,基于案例的推理,我们提出的基于案例的推理系统模型的建议推理,并提供了应用于示例网络安全的修改案例的推理系统的示例场景。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号