<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Learning, Simulating, and Predicting Adversary Attack Behaviors for Proactive Cyber Defense</article-title>
      </title-group>
      <contrib-group>
        <aff id="aff0">
          <label>0</label>
          <institution>83 Lomb Memorial Drive</institution>
          ,
          <addr-line>Rochester NY, 14623, USA (Tel) 1-585-475-2987 (Fax) 1-585-475-4084</addr-line>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Shanchieh Jay Yang</institution>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2004</year>
      </pub-date>
      <fpage>370</fpage>
      <lpage>379</lpage>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Proactive Cyber Defense</title>
      <p>In 2016, the cyberthreat landscape showcased advanced attack techniques, escalated attack
frequency, and high levels of adversarial sophistication (Kulkarni 2016). Conventional
cyberattack management is response driven, with organizations focusing their efforts on
detecting Indicators of Compromise, or threats (Kulkarni 2016). This reactive approach has
limited efficacy, as it does not capture advanced and sophisticated adversaries, mutating or
unknown malware, living-off-the-land techniques, or new variants being deployed (Kulkarni
2016). Furthermore, responding to incidents after the attack has occurred is costly for two
reasons. First, the attack has successfully occurred and damage has occurred in the form of data
theft, system manipulation, service/functionality disruption, or the like, which is costly to fix
(Barnum 2013). Second, during the attack, the adversary may have established several footholds
in different parts of the targeted system. Identifying and eradicating these footholds are costly
with regards to manpower and time (Barnum 2013).</p>
      <p>The average time taken to identify and contain data breaches caused by malicious or
criminal attacks was 229 and 82 days, respectively, and cybercrime detection and recovery
activities accounted for more than 55 percent of total internal company activity costs in FY 2016
(Ponemon 2016). US organizations had the highest average cost of cybercrime ($17.36 million),
with cybercrime costs in Germany and the UK averaging at $7.84 million and $7.21 million,
respectively (Ponemon 2016). There is thus an immediate need for a paradigm shift in the area of
cybersecurity. Security experts are calling for anticipatory or proactive defense measures that
focus on Indicators of Attack that identify adversarial behavior and movement (Barnum 2013,
Kulkarni 2016). Doing so requires a timely comprehension and predictive analysis of adversary
decision-making capacities, which are currently downplayed in existing research.</p>
      <p>Imagine a theoretically grounded system that learns, simulates, and predicts the attack
progressions of adversaries of different intents, tactics, capabilities, and preferences. Through
limited data accompanied with theoretical explanation, the system learns one or few adversary
behaviors with salient features, extrapolates from the learned behaviors to many simulated ones,
and generates plausible future activities based on the observed and extrapolated behaviors. The
extrapolated behaviors and plausible futures can be key ingredients of proactive cyber defense
measures, including providing anticipatory intelligence to human and autonomous agents. The
following section provides a brief description of interdisciplinary research directions that address
some of the current gaps towards such a system.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Theoretically Grounded Learning, Simulation, and Prediction</title>
      <p>Criminology Theories: According to Routine Activity Theory (RAT), a criminological theory,
crime is more likely to occur when three elements converge in space and time: (i) a capable
offender, (ii) a suitable victim or target, and (iii) the absence of capable guardianship (Cohen &amp;
Felson 1979). RAT offers more about where and when crimes are likely to occur (when the three
elements converge) than about why crime is likely to happen (why and how this convergence
results in crime) (Wikstrom &amp; Treiber 2016). Furthermore, the interaction of the three RAT
elements is dynamic and shifts as the cyberattack progresses (Sutton 2012).</p>
      <p>In the criminological discipline, ‘crime scripts’ provide a “standardized, systematic and
comprehensive understanding of the crime commission processes” (Leclerc 2016; Cornish &amp;
Clarke 2002). Crime scripts also help identify the decisions, actions, and resources that are
needed at each stage for the successful completion of the crime (Leclerc 2016). In the context of
cybercrime, as conducted by state actors, cyber criminals, hacktivists, etc., crime scripts are
captured by intrusion chains. Barnum’s (2013) intrusion chain model (Figure 1) illustrates how
adversaries study their targets, break into the targeted system, establish footholds, pivot and
move laterally to strengthen their presence, and repeat the process until their objectives are
completed.</p>
      <p>Computational Techniques: Independent of the criminology theories, several probabilistic
models have been developed to represent the interdependencies between system vulnerabilities
and observables of malicious activities (Qin 2004, Fava 2008, Noel 2009, Yang 2014). This set
of works infer the probabilistic dependencies using machine learning through observed malicious
activities and/or based on specific properties of system exploits. While the learned models might
reflect, implicitly, the adversarial behavior and be used to predict attack actions, they are limited
in criminological/behavioral grounding and lack the ability to explain why and how attackers
make specific movements. In addition, it is unlikely one will have ample data to
comprehensively learn about cyber adversaries given the vast and fast-changing attack landscape
and tactics. This calls for a new solution where limited data can be used to learn salient features
and extrapolate to additional attack scenarios representing a broader spectrum of evolving
adversarial behaviors.</p>
      <p>Figure 2 shows a framework where observables of cyberattacks are fed to both ASSERT –
an ensemble learning system that continuously creates and refines hypothesized attack models by
integrating Dynamic Bayesian Network (DBN), Clustering, and Generative Adversarial Network
(GAN), and CASCADES – a simulator that generates attack scenarios utilizing Monte-Carlo and
Importance Sampling over the attack action space subject to attacker capability, opportunity,
intent, and preference (Moskal 2014, Krall 2016, Moskal 2017). The two systems also feed to
each other to enhance the learning process through simulated data and to provide salient features
that can be used to guide simulation.</p>
      <sec id="sec-2-1">
        <title>Limited observables of malicious activities</title>
      </sec>
      <sec id="sec-2-2">
        <title>Salient Features &amp;</title>
      </sec>
      <sec id="sec-2-3">
        <title>Early Indicators</title>
      </sec>
      <sec id="sec-2-4">
        <title>Critical &amp; Likely</title>
      </sec>
      <sec id="sec-2-5">
        <title>Scenarios</title>
      </sec>
      <sec id="sec-2-6">
        <title>CASCADES: Cyber Attack Scenario</title>
        <p>&amp; Network Defense Simulator</p>
      </sec>
      <sec id="sec-2-7">
        <title>ASSERT: Attack Strategy</title>
      </sec>
      <sec id="sec-2-8">
        <title>Synthesis &amp; Ensemble Prediction</title>
        <p>Because cyberattack data is limited and evolving without ground truth of agent behaviors,
ASSERT must extract features through a carefully crafted GAN, use these features to create
DBN-based attack models, and evaluate the quality of observable-model pairing using the
concept of clustering. Current works have shown success in dynamically creating attack models
(Strapp 2014) and refine them with a cluster validity index (Saxton rev). Attack models resulting
from this process may also enhance the learning process in GAN. Meanwhile, referencing the
features and models from ASSERT as well as a dynamic criminological theory, CASCADES
may generate simulated attack scenarios along with observables to complement the limited
realworld data.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3. Transformative Impact</title>
      <p>Cyber defense must be proactive, utilizing anticipatory intelligence that enables actionable
resilience. A theoretical grounded learning, simulation, and prediction system will be a key to
enhance the intelligence of human and autonomous agents. A novel ensemble of advances in
machine learning and simulation that incorporates the dynamics of cyber adversary decision
making process will be at the frontline to bring forth this new era of cyber defense.</p>
    </sec>
    <sec id="sec-4">
      <title>References</title>
      <p>Barnum, S. (2013). Standardizing Cyber Threat Intelligence Information with the Structured
Threat Information eXpression (STIX™). MITRE Corporation, Retrieved July 2016. Online at
http://www.mitre.org/sites/default/files/publications/stix.pdf
Cohen, L. E., &amp; M. Felson (1979). Social Change and Crime Rate Trends: A Routine Activity
Approach. American Sociological Review, 44, 588–608.</p>
      <p>Cornish, D. B., &amp; R.V. Clarke (2002). Analyzing Organized Crimes. In A. Piquero &amp; S. G.
Tibbetts (Eds.), Rational choice and criminal Behavior: Recent research and future challenges.
New York: Routledge.</p>
      <p>Fava, D. S. (2008), S. R. Byers, and S. J. Yang. Projecting cyberattacks through variable-length
Markov models. IEEE Transactions on Information Forensics and Security, 3(3):359–369,
September 2008.</p>
      <p>Krall A. (2016), M. E. Kuhl, S. J. Yang, and S. Moskal, “Estimating the likelihood of Cyber
Attack Penetration using Rare-event Simulation,” in Proceedings of 2016 IEEE Symposium
Series on Computational Intelligence (IEEE SSCI 2016), December 6-9, Athens, Greece.
Leclerc, B. (2016). "Crime Scripts" In Wortley, R., &amp; Townsley, M. (Eds.), Environmental
criminology and crime analysis. Routledge.</p>
      <p>Moskal, S. (2014), B. Wheeler, D. Kreider, M. E. Kuhl, and S. J. Yang, “Context Model Fusion
for Multistage Network Attack Simulation,” in Proceedings of IEEE Military Communications
Conference (MILCOM’14), Baltimore, MD, October 6-8, 2014.</p>
      <p>Moskal, S. (2017), S. J. Yang, and M. Kuhl, “Cyber Threat Assessments via Attack Scenario
Simulation over Integrated Adversary and Network Modeling Approach,” accepted to appear in
Journal of Defense Modeling and Simulation.</p>
      <p>Noel, S. (2009) and S. Jajodia. Advanced vulnerability analysis and intrusion detection through
predictive attack graphs. Critical Issues in C4I, AFCEA Solutions Series. International Journal of
Command and Control, 2009.</p>
      <p>Ponemon Institute. (2016). “2016 Cost of Data Breach Study: Global Analysis”. Retrieved
January 10, 2017. Online at https://ssl.www8.hp.com/ww/en/secure/pdf/4aa5-5207enw.pdf</p>
      <p>Rege, A. (2016), “Incorporating the Human Element in Anticipatory and Dynamic Cyber
Defense,” in Proceedings of the 4th International Conference on Cybercrime and Computer
Forensics (ICCCF). IEEE, June 12-14, 2016, Vancouver, Canada.</p>
      <p>Saxton, J., S. J. Yang, &amp; A. Okutan (rev), “Dynamic Model Generation and Classification of
Network Attacks,” under review.
Sutton, M. (2012). Contingency Makes or Breaks the Thief: Introducing the Perception
Contingency Process Hypothesis. Retrieved February 5, 2017. Online at
https://www.bestthinking.com/articles/science/social_sciences/sociology/contingency-makes-orbreaks-the-thief-introducing-the-perception-contingency-process-hypothesis</p>
    </sec>
  </body>
  <back>
    <ref-list />
  </back>
</article>