arXiv · 2104.10319
Evidential Cyber Threat Hunting
Abstract
A formal cyber reasoning framework for automating the threat hunting process is described. The new cyber reasoning methodology introduces an operational semantics that operates over three subspaces -- knowledge, hypothesis, and action -- to enable human-machine co-creation of threat hypotheses and protective recommendations. An implementation of this framework shows that the approach is practical and can be used to generalize evidence-based multi-criteria threat investigations.
Explore related subjects
Keep this discovery
Frederico Araujo, Dhilung Kirat, Xiaokui Shu, Teryl Taylor, Jiyong Jang. 2021-04-21. Evidential Cyber Threat Hunting. https://arxiv.org/abs/2104.10319
Cite the original work for its findings. Save a collection to share your selection of sources.