作者: Paulo Shakarian , Gerardo I. Simari , Andrew Ruef , Eric Nunes
DOI:
关键词:
摘要: A major challenge in cyber-threat analysis is combining information from different sources to find the person or group responsible for cyber-attack. It one of most important technical and policy challenges cyber-security. The lack ground truth an individual attack has limited previous studies. In this paper, we take a first step towards overcoming limitation by building dataset capture-the-flag event held at DEFCON, propose argumentation model based on formal reasoning framework called DeLP (Defeasible Logic Programming) designed aid analyst attributing We build models latent variables reduce search space culprits (attackers), show that reduction significantly improves performance classification-based approaches 37% 62% identifying attacker.