Science of Security Session Proposals for RSA 2018
I wanted to share that I submitted a Science of Security talk to the RSA 2018 call for speakers based on the latest commercially available advancements in cybersecurity science and AI industry areas. Session details below.
Science of Security: Explainable AI for Integrated Adaptive Cyber Defense
This session will look at the intersection of cybersecurity science, artificial intelligence, and integrated adaptive cyber defense to deploy a scientific, evidence-based foundation for vastly improved cyber security operations by automation of their most highly-prized resource: the logic and experience of the human analyst. Learn how information security organizations can be more efficient and effective at cyber defense automation and orchestration with the augmented intelligence provided by explainable AI and cybersecurity science.
Automate what was previously solely a human task in frameworks such as the Integrated Adaptive Cyber Defense (IACD), a collaboration between NSA, DHS, Johns Hopkins APL and many industry leading vendors. IACD addresses the problem of cyber defense in two key areas: 1) Automates cyber defense tasks currently performed by human defenders, and 2) Shares threat information with other enterprises. IACD provides a reference architecture and specifications for the automation and orchestration of the cyber OODA Loop of Sensing, Sense-making, Decision-making, and Acting.
Within security automation and orchestration, a lot of focus has been on the last stage of the cyber OODA Loop, acting, with the rise of security orchestration solutions that primarily focus on playbooks that automate mechanistic actions with scripts. This session will focus on the automation and orchestration of security domain knowledge for making sense of the situation and decisions about what action to take for resolution. Using both machine learning and AI knowledge representation and reasoning to automate the claim + evidence + scientific reasoning = scientific argument process with AI-driven playbooks to deliver fully explainable AI results for automated sense-making and decision-making across security operations.
The AI knowledge representation and reasoning enables the security data feeds, sources, and analytic outputs to be organized into semantic knowledge graphs using the object-based production (OBP) methodology which enables the discovery of the 'unknown unknowns' using activity-based intelligence (ABI) tradecraft captured in AI-driven playbooks. OBP and ABI are related analysis methodologies that rapidly integrates data from multiple sources to discover relevant patterns, determine and identify change, and characterize those patterns to create decision advantage and drive the sensing, sense-making, decision-making, and acting in the cyber environment.