Symbolic Reasoning in the Cyber Security Domain

Michael Kandefer, Stuart C. Shapiro, Adam Stotz, Moises Sudit · 2007

Cyber Security can benefit greatly from the association and combination of data and information from multiple sources. A data repository of system vulnerabilities, a network scanning tool, and the advice of a systems analyst trained in cyber security can all aid in identifying and preventing intruders. Previous attempts at information fusion in cyber security have largely concerned themselves with the tangible information sources, but this ignores an important resource in solving problems in this particular domain --- the cyber security expert's reasoning process. The National Center for Information Fusion (NCMIF) has begun implementing a solution that partially automates the cyber security expert in the intrusion detection process through a combination of information fusion techniques and symbolic reasoning, using the SNePS knowledge representation, reasoning, and acting system. Our methodology approaches cyber security problems by fusing information from external information repositories into a SNePS-based agent‟s knowledge base. We have identified five information sources that are useful: the background knowledge of a cyber security subject matter expert (SME); Nessus security scan reports; the Common Vulnerabilities and Exposures (CVE) database; and INFERD template graphs. The SNePS system makes use of higher-order logic to represent information about the external world. Facts are represented as proposition-valued terms, and the SME‟s reasoning procedures are represented as logical rules.

Read the paper · More papers on PaperTik