A formal cyber reasoning framework for automating the threat hunting process is described. The new cyber reasoning methodology introduces an operational semantics that operates over three subspaces -- knowledge, hypothesis, and action -- to enable human-machine co-creation of threat hypotheses and protective recommendations. An implementation of this framework shows that the approach is practical and can be used to generalize evidence-based multi-criteria threat investigations.
翻译:新的网络推理方法引入了一种可操作的语义,在三个子空间(知识、假设和行动)上运作,使人类机器能够共同产生威胁假设和保护性建议,实施这一框架表明,这一方法是实用的,可以用于普及基于证据的多标准威胁调查。