Conceptual Design of Machine Intelligence Offensive Cyber Operations

Garba S. Abdullahi, Uche Magnus Mbanaso, Chukwubuikem J. Elochukwu, Sadiq A. Muhammad · 2024

The rapid advancement of Machine Intelligence (MI) and its associated technologies, including Artificial Intelligence (AI), Machine Learning (ML), and Deep Learning (DL), is driving the development of innovative applications across multiple sectors. One area of interest is Cyber Operations (CO), which involves using cyberspace capabilities by organized groups or nation-states to achieve specific objectives in or through cyberspace. CO is commonly viewed from two perspectives, Defensive Cyber Operation (DCO) and Offensive Cyber Operation (OCO), representing opposing operational principles in contemporary security operations. The MI field is experiencing a surge in quantity and complexity, with global growth and advancements in skills and capabilities, all while being developed under strict confidentiality. This study proposes a Machine Intelligence Cyber Operations (MICO) framework for developing an intelligent system for cyber operations. It then created a proof-of-concept artefact to demonstrate the practical application of the MICO framework in the Reconnaissance phase of OCO. A mixed-method research approach was employed, combining qualitative data from the focus group technique and synthesis of existing cybersecurity frameworks with quantitative data based on experiments and requirement analysis specification. We adopted the Design Science Research (DSR) strategy to design the MICO framework and proof of concept. The qualitative phase of the mixed method gathered insights from cybersecurity experts to understand critical doctrines, cultural aspects, and challenges in current cyber operation practices, which refined the framework's design. On the side of MI, experiments were conducted on dataset construction and algorithms to evaluate and optimise the design. We identified the Support Vector Regressor as the most effective model for predicting target vulnerability scores, achieving a Mean Squared Error (MSE) of 0.0055, and the Random Forest Classifier for cyberattack prediction, achieving an accuracy of 0.9997 and F1-score of 0.9999 when trained on a 32768x27 dataset. The above outcome is currently used in the reconnaissance phase to prospectively establish strong performance in classifying and predicting potent cyberattacks for OCO deployment. This unique study demonstrates the potential of MI in enhancing OCO and provides a foundation for future research in this area.

Read the paper · More papers on PaperTik