LSTM-based text analysis to automatically adapt cyberattack detection capabilities
摘要
Detection capabilities enable the timely discovery of cybersecurity events and anomalies and, therefore, potential incidents. These capabilities are primarily based on continuous monitoring mechanisms and situational awareness procedures. The constant evolution of the threat landscape and attack patterns makes selecting, deploying, and configuring these mechanisms and procedures a challenging task. Especially if one seeks, as has been the case so far, a set of detection capabilities that can be designed and deployed once and remain static over time. This paper proposes a method that improves detection capabilities performance once a set of Tactics, Techniques and Procedures (TTPs) is observed within an infrastructure. New detection capabilities can be introduced, or the pre-existing ones can be appropriately reconfigured. Deep Learning, precisely Long Short-Term Memory (LSTM) recurrent neural networks, is used to predict these TTPs. The proposed approach is based on analysing malware analysis reports and then deciding the required adaptations. A prototype of the proposed method is implemented and used to validate it within a test case.