CE39 - Sécurité globale, résilience et gestion de crise, cybersécurité 2023

AutoNomic Cybersecurity with adversarIal Leaning and Explanation – ANCILE

Submission summary

ANCILE proposes a new generation of Security Orchestration Automation and Response (SOAR) framework refining a generic autonomic computing architecture and extending the State-of-the-Art (SotA) with three innovations.

The first is the integration of four intrusion autonomic detection methods: both probabilistic attack signature recognition and statistical anomaly signaling on both network and endpoint.

The second is feeding these four signals to an autonomic pipeline of multistep stealth attack plan recognition followed by search for the mitigation plans that optimize multiple objectives such as availability, confidentiality, integrity, safety, and frugality. The actions in these plans are network traffic re-routing by a software defined network controller and provisioning, for attacked critical services, of redundant, alternative implementations of these service by containerized technological stacks free of known vulnerabilities.

The third innovation is adversarial co-learning of an attack planner supporting decisions of a red team of ethical hackers, with a defense pipeline of intrusion detectors, attack plan recognizer and mitigation planner, supporting decisions of a blue Computer Security Incident Response Team (CSIRT).

The first two innovations target improving defense against Advanced Persistent Threats (APT), while the third targets improving defense against zero-day attacks. Due to the presence humans in the decision loop the latter innovation also requires innovating in the explanation of inference with probabilistic rule bases implementing all models except the statistical anomaly detectors.

The security improvements of this new generation SOAR will be measured by: (a) the Brier Skill Score (BSS) of the individual anomaly and intrusion event detectors and the multistep stealth attack plan recognizer and (b) the multidimensional quality of service loss reduction achieved by executing the mitigation plans.

Project coordination

Bénédicte LEGRAND (CENTRE DE RECHERCHE EN INFORMATIQUE)

The author of this summary is the project coordinator, who is responsible for the content of this summary. The ANR declines any responsibility as for its contents.

Partnership

GATEWATCHER
LIST Luxembourg Institute of Science and Technology
GROUPE ESIEA
CRI CENTRE DE RECHERCHE EN INFORMATIQUE
LAB-STICC Laboratoire des Sciences et Techniques de l'Information, de la Communication et de la Connaissance

Help of the ANR 396,516 euros
Beginning and duration of the scientific project: April 2024 - 42 Months

Useful links

Explorez notre base de projets financés

 

 

ANR makes available its datasets on funded projects, click here to find more.

Sign up for the latest news:
Subscribe to our newsletter