Cross-level Knowledge Representation and Causal Reasoning for Interpretable Security Incident Understanding and Prediction – CKRISP
Despite the success of AI-based attack detection and classification solutions, they still suffer from limited coverage in terms of attack behaviour variety in the training data as well as the lack of interpretability of AI detection models. The main contribution of CKRISP is dedicated to addressing these challenges from four perspectives. First, we will investigate the combination of AI systems such as, e.g., Large Language Models (LLM), and human-monitored cyber security knowledge graph (CSKG) for understanding, predicting and exploring new cyberattack behaviours via Human-AI interaction. The powerful LLMs can help identify entities and predict relations between entities from cyber threat reports and low-level run-time behaviour logs. CSKG can then be built automatically based on extracted knowledge about specific attack scenarios. The attack knowledge graph can substantially help human analysts verify the AI-based attack detection results and facilitate human analysts' inspection of new attacks. Second, we will elaborate further on the prediction of attack behaviours by organizing AI-assisted reasoning with inputs from security incidents collected from various sensors, like IDS, and manual inspection results of human analysts. It will help assess the vulnerability of a target IT system and reach an initial step of AI-assisted security response based on the detected incidents. Third, we will further propose data generation methods to produce synthetic normal/attack behaviour data to enrich training data and improve the robustness of AI-based detection methods based on the extracted knowledge representation and causalities of attacks. Finally, new visualisation and interaction interfaces will be developed in this project to simplify the human-AI interaction. These interfaces are expected to be intuitive and user-friendly so that both technical staff (analysts) and non-technical staff (managers) can effectively interact with the results, respond quickly, and make more efficient decisions.
Project coordination
Yufei Han (Centre Inria de l’Université de Rennes)
The author of this summary is the project coordinator, who is responsible for the content of this summary. The ANR declines any responsibility as for its contents.
Partnership
CEA Commissariat à l'Energie Atomique et aux Energies Alternatives
EURECOM EURECOM
Centre Inria de l'Université de Rennes Centre Inria de l’Université de Rennes
TSP Télécom SudParis
Help of the ANR 665,613 euros
Beginning and duration of the scientific project:
September 2023
- 42 Months