Extending Case-Based Reasoning (CBR) Approaches to Semi-automated Network Alert Reporting

Abstract

A substantial amount of cyber security analyst time is spent handling well-known and na ve threats and policy violations on the local network. This includes both the time spent actually identifying and analyzing the activity as well as generating and filing reports associated with the activity. With increasing concern over advanced persistent threats, there is an interest in the development of techniques to automatically handle well-known threats and policy violations. We propose extensions to existing case-based reasoning approaches to support the unique requirements of cybersecurity report generation. Specifically, we consider the fact that we are reporting on hostile actors that will attempt to game the system or manipulate the system to actually aid the actors in obfuscating their activity. In this report, we describe the need for automated reporting, the applicability of case-based reasoning, our proposed extension to the standard case-based reasoning system model, and provide examples of the modified case-based reasoning system as applied to example cybersecurity scenarios.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Apr 01, 2013
Accession Number
ADA584553

Entities

People

  • Robert F. Erbacher
  • Steve E. Hutchinson

Organizations

  • United States Army Research Laboratory

Tags

Communities of Interest

  • Counter WMD
  • Cyber

DTIC Thesaurus Topics

  • Artificial Intelligence
  • Cognitive Science
  • Computer Network Security
  • Computer Networks
  • Computer Programs
  • Computer Science
  • Computers
  • Control Systems
  • Cybersecurity
  • Demographic Cohorts
  • Detection
  • Intrusion Detection
  • Intrusion Detection Systems
  • Intrusion Detectors
  • Malware
  • Operating Systems
  • Security

Fields of Study

  • Computer science

Readers

  • Artificial Intelligence
  • Cybersecurity.
  • Systems Analysis and Design

Technology Areas

  • Cyber