A Case-Based Reasoning Approach for the Cybersecurity Incident Recording and Resolution

被引:5
|
作者
Nunes, Raul Ceretta [1 ]
Colome, Marcelo [1 ]
Barcelos, Fabio Andre [1 ]
Garbin, Marcelo [1 ]
Paulus, Gustavo Bathu [1 ]
De Lima Silva, Luis Alvaro [1 ]
机构
[1] Univ Fed Santa Maria, Appl Comp Dept, Av Roraima 1000, BR-97105900 Santa Maria, RS, Brazil
关键词
Cybersecurity; information security; case-based reasoning; MANAGEMENT;
D O I
10.1142/S021819401940014X
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Intelligent computing techniques have a paramount importance to the treatment of cybersecurity incidents. In such Artificial Intelligence (AI) context, while most of the algorithms explored in the cybersecurity domain aim to present solutions to intrusion detection problems, these algorithms seldom approach the correction procedures that are explored in the resolution of cybersecurity incident problems that already took place. In practice, knowledge regarding cybersecurity resolution data and procedures is being under-used in the development of intelligent cybersecurity systems, sometimes even lost and not used at all. In this context, this work proposes the Case-based Cybersecurity Incident Resolution System (CCIRS), a system that implements an approach to integrate case-based reasoning (CBR) techniques and the IODEF standard in order to retain concrete problem-solving experiences of cybersecurity incident resolution to be reused in the resolution of new incidents. Different types of experimental results so far obtained with the CCIRS show that information security knowledge can be retained with our approach in a reusable memory improving the resolution of new cybersecurity problems.
引用
收藏
页码:1607 / 1627
页数:21
相关论文
共 50 条
  • [1] A CASE-BASED REASONING APPROACH TO THE RESOLUTION OF FAULTS IN COMMUNICATIONS NETWORKS
    LEWIS, L
    IFIP TRANSACTIONS C-COMMUNICATION SYSTEMS, 1993, 12 : 671 - 682
  • [2] Fault Resolution in Case-Based Reasoning
    Tran, Ha Manh
    Schoenwaelder, Juergen
    PRICAI 2008: TRENDS IN ARTIFICIAL INTELLIGENCE, 2008, 5351 : 417 - 429
  • [3] Using Case-Based Reasoning into a Decision Support Methodology for the Incident Resolution Control in IT.
    Freire de Mello, Thiago Dias
    Lopes, Expedito Carlos
    2015 10TH IBERIAN CONFERENCE ON INFORMATION SYSTEMS AND TECHNOLOGIES (CISTI), 2015,
  • [4] A case-based reasoning approach to zero anaphora resolution in Chinese texts
    Wu, Dian-Song
    Liang, Tyne
    COMPUTER PROCESSING OF ORIENTAL LANGUAGES, PROCEEDINGS: BEYOND THE ORIENT: THE RESEARCH CHALLENGES AHEAD, 2006, 4285 : 520 - +
  • [5] Using case-based reasoning to retrieve incident reports
    Johnson, CW
    FORESIGHT AND PRECAUTION, VOLS 1 AND 2, 2000, : 1387 - 1395
  • [6] Freeway incident management system based on case-based reasoning
    School of Transportation, Southeast University, Nanjing 210096, China
    Dongnan Daxue Xuebao, 2008, 5 (878-883):
  • [7] An approach for temporal case-based reasoning:: Episode-based reasoning
    Sánchez-Marré, M
    Cortés, U
    Martínez, M
    Comas, J
    Rodríguez-Roda, I
    CASE-BASED REASONING RESEARCH AND DEVELOPMENT, PROCEEDINGS, 2005, 3620 : 465 - 476
  • [8] A hybrid case adaptation approach for case-based reasoning
    Claudio A. Policastro
    André C. P. L. F. Carvalho
    Alexandre C. B. Delbem
    Applied Intelligence, 2008, 28 : 101 - 119
  • [9] A hybrid case adaptation approach for case-based reasoning
    Policastro, Claudio A.
    Carvalho, Andre C. P. L. F.
    Delbem, Alexandre C. B.
    APPLIED INTELLIGENCE, 2008, 28 (02) : 101 - 119
  • [10] A case-based reasoning approach for production scheduling
    Schmidt, G.
    Meyer, J.
    Wirtschaftsinformatik, 38 (01):