Modeling Analyst Intentions Using a Markov Chain for Investigative Action Recommendations
摘要
Despite the availability of detection tools and the automation of cyber security tasks, analysts are in demand because they can perform complex security investigations to identify and assess threats. Due to the shortage of expert analysts, it is necessary to employ systems that simplify and speed up security tasks. A promising solution is to employ recommender systems such as those used to enable shoppers to navigate enormous amounts of heterogeneous data in online marketplaces. This chapter describes a recommender system for incident response. The system recognizes seven analyst intentions during the investigative process and provides appropriate recommendations for an analyst’s next actions based on his/her most probable objectives. The recommender system is evaluated using four experiments and five datasets. The results demonstrate the validity of the model and the relevance of the recommendations, an important first step towards recommendations based on analyst intention recognition during incident response.