Intelligence graphs for threat intelligence and security policy validation of cyber systems

Vassilev, Vassil, Sowinski-Mydlarz, Viktor, Gasiorowski, Pawel, Ouazzane, Karim and Phipps, Anthony (2020) Intelligence graphs for threat intelligence and security policy validation of cyber systems. In: International Conference Artificial Intelligence and Applications ICAIA2020, 7-8 February 2020, Janakpuri, New Delhi, India.

Abstract

While the recent advances in Data Science and Machine Learning attract lots of attention in Cyber Security because of their promise for effective security analytics, Vulnerability Analysis, Risk Assessment and Security Policy Validation remain slightly aside. This is mainly due to the relatively slow progress in the theoretical formulation and the technologi-cal foundation of the cyber security concepts such as logical vulnerability, threats and risks. In this article we are proposing a framework for logical analysis, threat intelligence and validation of security policies in cyber systems. It is based on multi-level model, consisting of ontology of situations and actions under security threats, security policies governing the security-related activities, and graph of the transactions. The framework is validated using a set of scenarios describing the most common security threats in digital banking and a proto-type of an event-driven engine for navigation through the intelligence graphs has been im-plemented. Although the framework was developed specifically for application in digital banking, the authors believe that it has much wider applicability to security policy analysis, threat intelligence and security by design of cyber systems for financial, commercial and business operations.

Documents
5375:28548
[img]
Preview
ConferencePaper.pdf - Accepted Version

Download (655kB) | Preview
Details
Record
Statistics

Downloads

Downloads per month over past year



Downloads each year

View Item View Item