期刊论文详细信息
Frontiers in Psychology
Cognitive Models in Cybersecurity: Learning From Expert Analysts and Predicting Attacker Behavior
article
Vladislav D. Veksler1  Norbou Buchler1  Claire G. LaFleur1  Michael S. Yu2  Christian Lebiere2  Cleotilde Gonzalez2 
[1] U.S. Army Data & Analysis Center, United States;Department of Psychology, Carnegie Mellon University, United States
关键词: cyber-security;    cognitive modeling;    behavioral simulations;    deep learning;    reinforcement learning;    decision support;    XAI (eXplainable Artificial Intelligence);    human-agent teaming;   
DOI  :  10.3389/fpsyg.2020.01049
学科分类:社会科学、人文和艺术(综合)
来源: Frontiers
PDF
【 摘 要 】

Cybersecurity stands to benefit greatly from models able to generate predictions of attacker and defender behavior. On the defender side, there is promising research suggesting that Symbolic Deep Learning (SDL) may be employed to automatically construct cognitive models of expert behavior based on small samples of expert decisions. Such models could then be employed to provide decision support for non-expert users in the form of explainable expert-based suggestions. On the attacker side, there is promising research suggesting that model-tracing with dynamic parameter fitting may be used to automatically construct models during live attack scenarios, and to predict individual attacker preferences. Predicted attacker preferences could then be exploited for mitigating risk of successful attacks. In this paper we examine how these two cognitive modeling approaches may be useful for cybersecurity professionals via two human experiments. In the first experiment participants play the role of cyber analysts performing a task based on Intrusion Detection System alert elevation. Experiment results and analysis reveal that SDL can help to reduce missed threats by 25%. In the second experiment participants play the role of attackers picking among four attack strategies. Experiment results and analysis reveal that model-tracing with dynamic parameter fitting can be used to predict (and exploit) most attackers' preferences 40−70% of the time. We conclude that studies and models of human cognition are highly valuable for advancing cybersecurity.

【 授权许可】

CC BY   

【 预 览 】
附件列表
Files Size Format View
RO202108170004139ZK.pdf 1028KB PDF download
  文献评价指标  
  下载次数:3次 浏览次数:0次