Onto Hunt - A Semantic Reasoning Approach to Cyber Threat Hunting with Indicators of Behaviour

Robert Andrew Chetwyn, Martin Eian, Audun Jøsang · 2024

Cyber threat hunting offers a proactive threat analysis method which, discover previously unseen threat events and threat detection. However, threat hunting faces challenges with data overload, the constantly evolving threat landscape, and establishing context to particular security events. By leveraging semantic reasoning technologies and contextual analysis of interconnected security events, the study presents an enhanced method for threat hunting. Adversarial behaviours are modelled as Indicators of Behaviour - a series of low level to high level abstractions for reasoning over individually captured security events. The findings demonstrate a semantic gap between the representation of adversarial procedures and behaviours, and how to detect them. We also enhance limitations in the MITRE ATT &CK framework for detection logic. In utilising our method we find that adversarial procedures and behaviours can be represented both as a prose text description, a collection of abstractions, and inferred security events through the use of semantic reasoning.

Read the paper · More papers on PaperTik