Automated threat defense: a comprehensive survey on red and blue team automation using machine learning techniques
摘要
In recent years, cyber threats have become more complex and frequent. These threats compromise the confidentiality of users, the integrity of transactions, and the availability of services offered by organizations in different sectors. To defend against threat actors, organizations employ Red and Blue teams. Red teams conduct offensive security while blue teams commit to defensive efforts. However, the shortage of cybersecurity professionals and the increasing complexity of malicious activities reinforce the need for continuous improvement in threat defense. One possible direction to address these challenges is threat defense automation. This new paradigm empowers analysts to evaluate incidents at scale, enables continuous infrastructure monitoring, accelerates the training of new team members, and establishes standard defense methods that can be shared among multiple organizations. In this regard, Machine Learning (ML) is vital to threat defense automation and leverages organizational resources to generate insights and enable informed decisions. The main goal of this research is to conduct a survey on different solutions for threat defense automation using ML techniques. We focus on the operational functions adopted by red and blue teams in several application areas. We categorize existing efforts into these functions and also review datasets, knowledge graphs, simulation platforms, and Reinforcement Learning (RL) environments for threat defense automation solutions. In total, we analyze 138 research works, of which 35 present resources relevant to automated threat defense, 60 present automated red teaming solutions, and 43 present automated blue teaming solutions. Finally, we highlight critical research gaps and identify future directions in the automation of cyber threat defense.