IRSKG: Unified Intrusion Response System Knowledge Graph Ontology for Cyber Defense
Damodar Panigrahi, Shaswata Mitra, Subash Neupane, Sudip Mittal,, Benjamin A. Blakely

TL;DR
This paper introduces IRSKG, a unified knowledge graph ontology for intrusion response systems that enhances integration, automation, and adaptability in cyber defense, enabling more effective autonomous threat mitigation.
Contribution
The paper presents a novel ontology that unifies disparate monitoring sources and policies, improving automation and adaptability of intrusion response systems in cybersecurity.
Findings
Enables effective training of machine learning models for cyber defense
Supports dynamic updates to adapt to evolving threats
Facilitates autonomous system recovery with explainability
Abstract
Cyberattacks are becoming increasingly difficult to detect and prevent due to their sophistication. In response, Autonomous Intelligent Cyber-defense Agents (AICAs) are emerging as crucial solutions. One prominent AICA agent is the Intrusion Response System (IRS), which is critical for mitigating threats after detection. IRS uses several Tactics, Techniques, and Procedures (TTPs) to mitigate attacks and restore the infrastructure to normal operations. Continuous monitoring of the enterprise infrastructure is an essential TTP the IRS uses. However, each system serves different purposes to meet operational needs. Integrating these disparate sources for continuous monitoring increases pre-processing complexity and limits automation, eventually prolonging critical response time for attackers to exploit. We propose a unified IRS Knowledge Graph ontology (IRSKG) that streamlines the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Complex Network Analysis Techniques
MethodsOntology
