Security Analytics Framework Validation Based on Threat Intelligence

Viktor Sowinski‐Mydlarz, Vassil Vassilev, Karim Ouazzane, Anthony Phipps · 2022

Logical analysis of the ontology of digital security in banking helps us to identify the possible entry points for illegal access. The threats described in the ontology are detected by Machine Learning engines. The theoretical analysis is validated by verifying the framework and Machine Learning algorithms. Intelligence Graphs (original term) which are adding the actions to knowledge graphs to form workflows, are a base for validation of the framework through simulated execution of the scenarios specified in them. The output is a method for analysing live network traffic data (machine learning algorithm) combined with semantic model to give a hybrid framework for threat intelligence in digital banking, leading to a complete threat detection platform. The model is validated using operation workflows, namely 12 scenarios of banking “journeys” under the duress of various threats. In this work we are presenting the validation of the framework by simulation of the banking operations and transactions stemming from the Ontology of Digital Banking used as a model of the banking infrastructure (assets, vulnerabilities and threats included). This validation is based on the use of the Intelligence Graphs to demonstrate the capability of the framework to deal with typical scenarios by detecting the threats through ML, identifying them by checking the situations in which they appear in the ontology of threats, selecting appropriate counteraction using the security rules and planning their execution as containerized services. For better understanding of the subject matter, the authors would like to refer the reader to a previous article on general framework we developed.

Read the paper · More papers on PaperTik