Cyber attacking is easier than cyber defending—attackers only need to find one breach, while the defenders must successfully repel all attacks. This research demonstrates how cyber defenders can increase their capabilities by joining forces with eXplainable-AI (XAI) utilizing interactive human-machine collaboration. With a global shortfall of cyber defenders there is a need to amplify their skills using AI. Cyber asymmetries make propositional machine learning techniques impractical. Human reasoning and skill is a key ingredient in defense and must be embedded in the AI framework. For Human-Machine collaboration to work requires that the AI is an ultra-strong machine learner and can explain its models. Unlike Deep Learning, Inductive Logic Programming can communicate what it learns to a human. An empirical study was undertaken using six months of eavesdropped network traffic from an organization generating up-to 562K network events daily. Easier-to-defend devices were identified using a form of the Good-Turing Frequency estimator which is a promising form of volatility measure. A behavioral cloning grammar in explicit symbolic form was then produced from a single device's network activity using the compression algorithm SEQUITUR. A novel visualization was generated to allow defenders to identify network sequences they wish to explain. Interactive Inductive Logic Programming (the XAI) is supplied the network traffic meta data, sophisticated pre-existing cyber security background knowledge, and one recurring sequence of events from a single device to explain. A co-inductive process between the human cyber defender and the XAI where the human is able to understand, then refute and shape the XAI's developing model, to produce a model that conforms with the data as well as the original device designers programming. The acceptable model is in a form that can be deployed as an ongoing active cyber defense.
Cyber attacking is easier than cyber defending – attackers only need to find one breach, while the defenders must successfully repel all attacks. This preliminary work uses s(CASP) as a framework for modelling networks of devices, and their associated insecurities and defenses. Cyber defenders often need to reason with missing, uncertain, and contradictory evidence. This position paper demonstrates that cyber defenders can amplify their capabilities by joining forces with eXplainable-AI (XAI) utilising interactive human machine collaboration mediated through s(CASP) .
Besides Intel’s SGX technology, there are long-running discussions on how trusted computing technologies can be used to cloak malware. Past research showed example methods of malicious activities utilising Flicker, Trusted Platform Module, and recently integrating with enclaves. We observe two ambiguous methodologies of malware development being associated with SGX, and it is crucial to systematise their details. One methodology is to use the core SGX ecosystem to cloak malware; potentially affecting a large number of systems. The second methodology is to create a custom enclave not adhering to base assumptions of SGX, creating a demonstration code of malware behaviour with these incorrect assumptions; remaining local without any impact. We examine what malware aims to do in real-world scenarios and state-of-art techniques in malware evasion. We present multiple limitations of maintaining the SGX-assisted malware and evading it from anti-malware mechanisms. The limitations make SGX enclaves a poor choice for achieving a successful malware campaign. We systematise twelve misconceptions (myths) outlining how an overfit-malware using SGX weakens malware’s existing abilities. We find the differences by comparing SGX assistance for malware with non-SGX malware (i.e., malware in the wild in our paper). We conclude that the use of hardware enclaves does not increase the preexisting attack surface, enables no new infection vector, and does not contribute any new methods to the stealthiness of malware.
This paper proposes a logic-based machine learning approach called Acuity which is designed to facilitate user-guided elucidation of novel phenomena from evidence sparsely distributed across large volumes of linked relational data. The work builds on systems from the field of Inductive Logic Programming (ILP) by introducing a suite of new techniques for interacting with domain experts and data sources in a way that allows complex logical reasoning to be strategically exploited on large real-world databases through intuitive hypothesis-shaping and data-caching functionality. We propose two methods for rebutting or shaping candidate hypotheses and two methods for querying or importing relevant data from multiple sources. The benefits of Acuity are illustrated in a proof-of-principle case study involving a retrospective analysis of the CryptoWall ransomware attack using data from a cyber security testbed comprising a small business network and an infected laptop.
. The detection and prevention of computer security breaches is made very difficult by the continual development of sophisticated and innovative attacks. When a new threat is discovered, defenders must work hard and fast to understand its behaviour and develop effective counter-measures to avoid potentially serious consequences. The Cyber Threat Alliance estimates that, last year alone, one particularly potent attack known as CryptoWall-3 cheated victims out of several hundred million dollars worldwide by forcing them to pay ransoms to recover files it secretly encrypted on their machines [6]. At the time of writing, an improved attack called CryptoWall-4 is now grabbing headlines and wreaking havoc around the globe. This paper proposes an ILP method to assist experts in detecting and analysing cyber-attacks using data logs acquired by an eaves-dropping device placed in the host computer’s network to monitor various aspects of its communications traffic. Using CryptoWall-4 as a proof-of-principle case study, we show how ILP can be used to interactively learn rules describing malware behaviour that are comparable to those hand-crafted by a human expert.
Collaborative Data Mining is a setting where the Data Mining effort is distributed to multiple collaborating agents — human or software. The objective of the collaborative Data Mining effort is to produce solutions to the tackled Data Mining problem which are considered better by some metric, with respect to those solutions that would have been achieved by individual, non-collaborating agents. The solutions require evaluation, comparison, and approaches for combination. Collaboration requires communication, and implies some form of community. The human form of collaboration is a social task. Organizing communities in an effective manner is non trivial and often requires well defined roles and processes. Data Mining, too, benefits from a standard process. This chapter explores the standard Data Mining process CRISP-DM utilized in a collaborative setting.
In distributed, service-oriented environments, performance problem localization is required to provide self-healing capabilities and deliver the desired quality of service (QoS). This paper presents an automated approach to identifying system elements causing performance problems. Applying probabilistic inference to collected response time and elapsed time data, the approach 1) infers elapsed time for services where data is missing, 2) estimates the response time degradation caused by different services using the duration, abnormality and response time correlation of their elapsed times, and 3) identifies the services that are the most important causes of slow response time and yield the most benefit if recovered. The approach has been used to localize a performance problem on the test bed of a real-world service-oriented Grid. Evaluation using simulations shows that the approach consistently achieves better accuracy than traditional techniques in various service-oriented settings.
In heterogeneous and dynamic distributed systems like the grid, detailed monitoring of workload and its resulting system performance (e.g. response time) is required to facilitate performance diagnosis and adaptive performance tuning. In this paper, we present a workload monitoring infrastructure for this purpose. The infrastructure classifies and monitors workload across components in grids based on the open grid service architecture (OGSA) in an end-to-end manner. It provides the abilities to assess what components are involved in processing a work unit, to report time elapsed at these components, and to capture concurrency and isolate which components are critical to overall performance observed. These are enclosed in an automatically constructed Response Time Service Petri Net (RT-SPN) model. A tool is provided to accept queries about work units and visualise corresponding RTSPNs. The infrastructure is also designed and implemented so as to be portable, scalable and lightweight.
Continuous numeric prediction techniques known as model trees which build decision trees and then use linear regression at the terminal nodes are used to characterize resource consumption in a computer system. An advantage of model trees over time series and other traditional statistical models is the ability to add background knowledge to the model. Models are built using production data from several banks in collaboration with domain experts at those institutions. A demonstration of improving the models by adding background expert knowledge is given. An example of using model predictions to allow adaptive elements of an operating system to become more self-managing with respect to memory usage is also presented. Comparisons with other predictive techniques are made and advantages and disadvantages of using this technique in the operating system are discussed.
An Event Calculus program to control the navigation of a real robot was generated using Theory Completion techniques. This is an application of ILP in the non-observational predicate learning setting. This work utilized 1) extraction-case abduction; 2) the simultaneous completion of two, mutually related predicates; and 3) positive observations only learning. Given time-trace observations of a robot successfully navigating a model office and other background information, Theory Completion was used to induce navigation control programs in the event calculus. Such programs consisted of many clauses (up to 15) in two mutually related predicates. This application demonstrates that abduction and induction can be combined to effect nonobservational multi-predicate learning.
Intrusion detection is the identification of potential breaches in computer security policy. The objective of an attacker is often to gain access to a system that they are not authorized to use. The attacker achieves this by exploiting a (known) software vulnerability by sending the system a particular input. Current intrusion detection systems examine input for syntactic signatures of known intrusions. This work demonstrates that logic programming is a suitable formalism for specifying the semantics of attacks. Logic programs can then be used as a means of detecting attacks in previously unseen inputs. Furthermore the machine learning approach provided by Inductive Logic Programming can be used to induce detection clauses from examples of attacks. Experiments of learning ten different attack strategies to exploit one particular vulnerability demonstrate that accurate detection rules can be generated from very few attack examples.
Traditional Inductive Logic Programming (ILP) focuses on the setting where the target theory is a generalisation of the observations. This is known as Observational Predicate Learning (OPL). In the Theory Completion setting the target theory is not in the same predicate as the observations (non-OPL). This thesis investigates two alternative simple extensions to traditional ILP to perform non-OPL or Theory Completion. Both techniques perform extraction-case abduction from an existing background theory and one seed observation. The first technique -- Logical Back-propagation -- modifies the existing background theory so that abductions can be achieved by a form of constructive negation using a standard SLD-resolution theorem prover. The second technique -- SOLD-resolution -- modifies the theorem prover, and leaves the existing background theory unchanged. It is shown that all abductions produced by Logical Back-propagation can also be generated by SOLD-resolution; but the reverse does not hold. The implementation using the SOLD-resolution technique -- the ALECTO system -- was applied to the problems of completing context free and context dependant grammars; and learning Event Calculus programs. It was successfully able to learn an Event Calculus program to control the navigation of a real-life robot. The Event Calculus is a formalism to represent common-sense knowledge. It follows that the discovery of some common-sense knowledge was produced with the assistance of a machine.
Large and Tall buildings can be broadly classified into three groups: sprawling, squat, or tall. The decision to build a particular type of large building can be based on a vast number of attributes. A building construction expert's analysis of seventy international building projects was used as input to further decision support and data mining analyses. Decision models were developed that incorporated customer values of proposed construction project attributes. Data mining was used to model the feasibility of construction projects from their input attributes. On this basis, we propose a novel way of integrating data mining and decision support methods, where both techniques are used. In this approach both techniques are employed to utilize the same input vectors. While decision support models are designed to assess and possibly maximize utility. data mining models provide a test for feasibility.
Marko Bohanec合作论文数Jo?ef Stefan Institute;Department of Knowledge Technologies4
Steve Mckeever合作论文数OXFORD UNIVERSITY COMPUTING LABORATORY2