Employing PDDL Plan to Recommend Security Controls Against Cyberattacks
摘要
Cybersecurity is a constantly evolving field that could benefit most from the introduction of Artificial intelligence (AI). AI offers cybersecurity opportunities, for example, to improve attack modeling, prediction, and response. A promising field of research is AI planning, which involves the automated generation of action sequences to achieve specific goals. For example, in a logistic scenario, the goal could be satisfy a location, while in a vulnerability scenario, the goal can be defined as account credential is compromised). In this paper, we introduce an AI-based approach that uses the Planning Domain Definition Language (PDDL) to model the behavior of cyberattacks, specifically phishing and ransomware. Using an AI planner, we generate detailed attack steps and classify them into standard attack lifecycle phases, including reconnaissance, weaponization, delivery, exploitation, installation, and command & control. The classification is used to propose security controls that align with industrial frameworks such as the NIST Cybersecurity Framework and ISO 27001. The approach was evaluated using a scenario of a phishing attack, highlighting the effectiveness of the classifying attack steps and providing the countermeasures with compliance to de facto standards. The results highlight the potential of our approach to AI planning to provide a structured and proactive methodology to map and understand the behavior of cyberattacks and provide recommendations for specific protections according to compliance demands.