Conference item icon

Conference item

RicherPicture: Semi-automated cyber defence using context-aware data analytics

Abstract:
In a continually evolving cyber-threat landscape, the detection and prevention of cyber attacks has become a complex task. Technological developments have led organisations to digitise the majority of their operations. This practice, however, has its perils, since cybespace offers a new attack-surface. Institutions which are tasked to protect organisations from these threats utilise mainly network data and their incident response strategy remains oblivious to the needs of the organisation when it comes to protecting operational aspects. This paper presents a system able to combine threat intelligence data, attack-trend data and organisational data (along with other data sources available) in order to achieve automated network-defence actions. Our approach combines machine learning, visual analytics and information from business processes to guide through a decisionmaking process for a Security Operation Centre environment. We test our system on two synthetic scenarios and show that correlating network data with non-network data for automated network defences is possible and worth investigating further.
Publication status:
Published
Peer review status:
Peer reviewed

Actions


Access Document


Publisher copy:
10.1109/CyberSA.2017.8073399

Authors


More by this author
Institution:
University of Oxford
Oxford college:
Magdalen College
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author
More by this author
Institution:
University of Oxford
Division:
MPLS
Department:
Computer Science
Role:
Author


Publisher:
Institute of Electrical and Electronics Engineers
Host title:
International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA 2017)
Journal:
International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA 2017) More from this journal
Publication date:
2017-10-01
Acceptance date:
2017-04-12
DOI:


Pubs id:
pubs:689474
UUID:
uuid:9bc41f4c-60e8-4b77-9619-636b5dad7dea
Local pid:
pubs:689474
Source identifiers:
689474
Deposit date:
2017-04-13

Terms of use



Views and Downloads






If you are the owner of this record, you can report an update to it here: Report update to this record

TO TOP