paper-with-me

홈 › Papers

IRSKG: Unified Intrusion Response System Knowledge Graph Ontology for Cyber Defense

2024-11-23 · Damodar Panigrahi, Shaswata Mitra, Subash Neupane, Sudip Mittal, Benjamin A. Blakely

Cyberattacks are becoming increasingly difficult to detect and prevent due to their sophistication. In response, Autonomous Intelligent Cyber-defense Agents (AICAs) are emerging as crucial solutions. One prominent AICA agent is the Intrusion Response System (IRS), which is critical for mitigating threats after detection. IRS uses several Tactics, Techniques, and Procedures (TTPs) to mitigate attacks and restore the infrastructure to normal operations. Continuous monitoring of the enterprise infrastructure is an essential TTP the IRS uses. However, each system serves different purposes to meet operational needs. Integrating these disparate sources for continuous monitoring increases pre-processing complexity and limits automation, eventually prolonging critical response time for attackers to exploit. We propose a unified IRS Knowledge Graph ontology (IRSKG) that streamlines the onboarding of new enterprise systems as a source for the AICAs. Our ontology can capture system monitoring logs and supplemental data, such as a rules repository containing the administrator-defined policies to dictate the IRS responses. Besides, our ontology permits us to incorporate dynamic changes to adapt to the evolving cyber-threat landscape. This robust yet concise design allows machine learning models to train effectively and recover a compromised system to its desired state autonomously with explainability.

📄 PDF Abstract BibTeX arXiv:2411.15672

Code (0)

등록된 구현이 없습니다.

Methods 이 논문이 사용한 방법론

Ontology 설명 없음

Similar Papers 제목 키워드 기반

IRSDA: An Agent-Orchestrated Framework for Enterprise Intrusion Response

2025-11-24 · Damodar Panigrahi, Raj Patel, Shaswata Mitra, Sudip Mittal 외 arxiv

Modern enterprise systems face escalating cyber threats that are increasingly dynamic, distributed, and multi-stage in nature. Traditional intrusion detection and response systems often rely on static rules and manual wo…

Intrusion Detection

Domain Knowledge Aided Explainable Artificial Intelligence for Intrusion Detection and Response

2019-11-22 · Sheikh Rabiul Islam, William Eberle, Sheikh K. Ghafoor, Ambareen Siraj 외

Artificial Intelligence (AI) has become an integral part of modern-day security solutions for its ability to learn very complex functions and handling "Big Data". However, the lack of explainability and interpretability …

Explainable artificial intelligenceIntrusion DetectionNetwork Intrusion Detection

SoK: Knowledge is All You Need: Accelerating Last Mile Delivery for Automated Provenance-based Intrusion Detection with LLMs

2025-03-05 · Wenrui Cheng, Tiantian Zhu, Chunlin Xiong, Haofei Sun 외

Recently, provenance-based intrusion detection systems (PIDSes) have been widely proposed for endpoint threat analysis. However, due to the lack of systematic integration and utilization of knowledge, existing PIDSes sti…

AllIntrusion Detection

Learning Intrusion Response Strategies for OT Systems

2026-09-09 · Duc Huy Le, Rolf Stadler arxiv

Cyberattacks against Operational Technology (OT) systems, which monitor and control industrial processes, pose an increasing threat to essential societal services. For this reason, developing automated intrusion response…

An Intrusion Response System utilizing Deep Q-Networks and System Partitions

2022-02-16 · Valeria Cardellini, Emiliano Casalicchio, Stefano Iannucci, Matteo Lucantonio 외

Intrusion Response is a relatively new field of research. Recent approaches for the creation of Intrusion Response Systems (IRSs) use Reinforcement Learning (RL) as a primary technique for the optimal or near-optimal sel…

Reinforcement Learning (RL)Transfer Learning