Skip to search boxSkip to navigationSkip to main content

Learning About the Adversary

*Corresponding author for this work
  • Delft University of Technology
    ,
  • Rochester Institute of Technology
Research Output:
Chapter in Book/Report/Conference proceeding
Chapter

Abstract

The evolving nature of the tactics, techniques, and procedures used by cyber adversaries have made signature and template based methods of modeling adversary behavior almost infeasible. We are moving into an era of data-driven autonomous cyber defense agents that learn contextually meaningful adversary behaviors from observables. In this chapter, we explore what can be learnt about cyber adversaries from observable data, such as intrusion alerts, network traffic, and threat intelligence feeds. We describe the challenges of building autonomous cyber defense agents, such as learning from noisy observables with no ground truth, and the brittle nature of deep learning based agents that can be easily evaded by adversaries. We illustrate three state-of-the-art autonomous cyber defense agents that model adversary behavior from traffic induced observables without a priori expert knowledge or ground truth labels. We close with recommendations and directions for future work.

Bibliographic Information

Output type

Research Output:
Chapter in Book/Report/Conference proceeding
Chapter

Original language

English

Pages from-to (Number of pages)

Pages 105-132 (28 pages)

Publication milestones

  • Published - 2023

Publication status

Published - 2023

Publisher

Springer Verlag

Publication series

  • Publication series name: Advances in Information Security
    ISSN (Print): 1568-2633
    ISSN (Electronic): 2512-2193
    Volume: 87

Publication IDs

  • Scopus: 85162020864

Host publication title

Advances in Information Security