As cyberattacks continue to increase, detecting and performing remediation actions m is essential. This paper presents an approach to automate the countermeasures selection process to deal with a vulnerability exploitation performed by a cyberattack. We propose an approach to match two knowledge graphs, one from a vulnerability ontology, Vulnerability Description Ontology (VDO), and the other is the countermeasures knowledge graph, D3FEND, to mitigate cyberattack impacts. Our approach uses machine learning and an inference system to match entities from VDO and D3FEND to select candidate countermeasures to an attack. Our contribution aims to automatically select countermeasures intended to be part of an incident response playbook for a vulnerability. We show our approach application to a WannaCry use-case scenario. We validate our countermeasures selection approach by comparing the countermeasures automatically selected with those proposed in the literature for a WannaCry attack.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Matching Knowledge Graphs for Cybersecurity Countermeasures Selection

  • Kéren A. Saint-Hilaire,
  • Christopher Neal,
  • Frédéric Cuppens,
  • Nora Boulahia-Cuppens,
  • Makhlouf Hadji

摘要

As cyberattacks continue to increase, detecting and performing remediation actions m is essential. This paper presents an approach to automate the countermeasures selection process to deal with a vulnerability exploitation performed by a cyberattack. We propose an approach to match two knowledge graphs, one from a vulnerability ontology, Vulnerability Description Ontology (VDO), and the other is the countermeasures knowledge graph, D3FEND, to mitigate cyberattack impacts. Our approach uses machine learning and an inference system to match entities from VDO and D3FEND to select candidate countermeasures to an attack. Our contribution aims to automatically select countermeasures intended to be part of an incident response playbook for a vulnerability. We show our approach application to a WannaCry use-case scenario. We validate our countermeasures selection approach by comparing the countermeasures automatically selected with those proposed in the literature for a WannaCry attack.