RicherPicture: Semi-automated cyber defence using context-aware data analytics

In a continually evolving cyber-threat landscape, the detection and prevention of cyber attacks has become a complex task. Technological developments have led organisations to digitise the majority of their operations. This practice, however, has its perils, since cybespace offers a new attack-surfa...

Full description

Bibliographic Details
Main Authors: Erola, A, Agrafiotis, I, Happa, J, Goldsmith, M, Creese, S, Legg, P
Format: Conference item
Published: Institute of Electrical and Electronics Engineers 2017
_version_ 1826287269415223296
author Erola, A
Agrafiotis, I
Happa, J
Goldsmith, M
Creese, S
Legg, P
author_facet Erola, A
Agrafiotis, I
Happa, J
Goldsmith, M
Creese, S
Legg, P
author_sort Erola, A
collection OXFORD
description In a continually evolving cyber-threat landscape, the detection and prevention of cyber attacks has become a complex task. Technological developments have led organisations to digitise the majority of their operations. This practice, however, has its perils, since cybespace offers a new attack-surface. Institutions which are tasked to protect organisations from these threats utilise mainly network data and their incident response strategy remains oblivious to the needs of the organisation when it comes to protecting operational aspects. This paper presents a system able to combine threat intelligence data, attack-trend data and organisational data (along with other data sources available) in order to achieve automated network-defence actions. Our approach combines machine learning, visual analytics and information from business processes to guide through a decisionmaking process for a Security Operation Centre environment. We test our system on two synthetic scenarios and show that correlating network data with non-network data for automated network defences is possible and worth investigating further.
first_indexed 2024-03-07T01:56:07Z
format Conference item
id oxford-uuid:9bc41f4c-60e8-4b77-9619-636b5dad7dea
institution University of Oxford
last_indexed 2024-03-07T01:56:07Z
publishDate 2017
publisher Institute of Electrical and Electronics Engineers
record_format dspace
spelling oxford-uuid:9bc41f4c-60e8-4b77-9619-636b5dad7dea2022-03-27T00:31:12ZRicherPicture: Semi-automated cyber defence using context-aware data analyticsConference itemhttp://purl.org/coar/resource_type/c_5794uuid:9bc41f4c-60e8-4b77-9619-636b5dad7deaSymplectic Elements at OxfordInstitute of Electrical and Electronics Engineers2017Erola, AAgrafiotis, IHappa, JGoldsmith, MCreese, SLegg, PIn a continually evolving cyber-threat landscape, the detection and prevention of cyber attacks has become a complex task. Technological developments have led organisations to digitise the majority of their operations. This practice, however, has its perils, since cybespace offers a new attack-surface. Institutions which are tasked to protect organisations from these threats utilise mainly network data and their incident response strategy remains oblivious to the needs of the organisation when it comes to protecting operational aspects. This paper presents a system able to combine threat intelligence data, attack-trend data and organisational data (along with other data sources available) in order to achieve automated network-defence actions. Our approach combines machine learning, visual analytics and information from business processes to guide through a decisionmaking process for a Security Operation Centre environment. We test our system on two synthetic scenarios and show that correlating network data with non-network data for automated network defences is possible and worth investigating further.
spellingShingle Erola, A
Agrafiotis, I
Happa, J
Goldsmith, M
Creese, S
Legg, P
RicherPicture: Semi-automated cyber defence using context-aware data analytics
title RicherPicture: Semi-automated cyber defence using context-aware data analytics
title_full RicherPicture: Semi-automated cyber defence using context-aware data analytics
title_fullStr RicherPicture: Semi-automated cyber defence using context-aware data analytics
title_full_unstemmed RicherPicture: Semi-automated cyber defence using context-aware data analytics
title_short RicherPicture: Semi-automated cyber defence using context-aware data analytics
title_sort richerpicture semi automated cyber defence using context aware data analytics
work_keys_str_mv AT erolaa richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics
AT agrafiotisi richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics
AT happaj richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics
AT goldsmithm richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics
AT creeses richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics
AT leggp richerpicturesemiautomatedcyberdefenceusingcontextawaredataanalytics