Cyber Threat Hunting Through Automated Hypothesis and Multi-Criteria Decision Making

Antonio Horta, Anderson Fernandes Pereira dos Santos · 2020

There are sophisticated cyber attacks that pose a high risk to institutions, especially when they are carefully planned and victims are unable to identify them. This is a preliminary result of executing the high-level cyber threat hunting through automated hypothesis-making and multi-criteria decision making using the binary attack-chaining tables identified in the networks. Firstly, the concepts required for threats modeling and the process of knowledge discovery in databases focused on high-level threat hunting were introduced. After, the knowledge discovered was used in an experiment that applied and evaluated the effectiveness of machine learning and decision-making algorithms in the method proposed to prioritize hypotheses in the screening phase. In addition, an automated hypothesis-making method to be used in production environments was also proposed. Finally, the results achieved in the experiment demonstrated that high-level threat hunting is a viable and more efficient alternative compared to manual process.

Read the paper · More papers on PaperTik