BEGIN:VCALENDAR VERSION:2.0 X-WR-CALNAME:EventsCalendar PRODID:-//hacksw/handcal//NONSGML v1.0//EN CALSCALE:GREGORIAN BEGIN:VTIMEZONE TZID:America/New_York LAST-MODIFIED:20240422T053451Z TZURL:https://www.tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZNAME:EDT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 DTSTART:19700308T020000 RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU END:DAYLIGHT BEGIN:STANDARD TZNAME:EST TZOFFSETFROM:-0400 TZOFFSETTO:-0500 DTSTART:19701101T020000 RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU END:STANDARD END:VTIMEZONE BEGIN:VEVENT CATEGORIES:College of Arts and Sciences,College of Engineering,Thesis/Disse rtations DESCRIPTION:Thesis Advisor: Dr. Gokhan Kul - Computer & Information Science ÌýCommittee Members:ÌýDr. Debarun Das - Computer & Information ScienceDr. Ashokkumar Patel - Computer & Information ScienceÌýAbstract: Adversarial R isk Analysis (ARA) offers a decision-theoretic alternative to game-theoret ic models of network defense. Instead of assuming that attacker and defend er know each other's payoffs and settle into an equilibrium, the defender reasons under subjective uncertainty about adversary behavior and picks up the security posture that maximizes expected utility. Adoption has been l imited for one narrow reason: the utility functions at the center of the a nalysis are assumed rather than measured. This thesis derives them from pu blished cyber threat intelligence.The first half builds the empirical foun dation. We process MITRE ATT&CK v16 into 4,849 tactic-ordered campaign cha ins from 33 documented campaigns and train a hybrid forecasting model on t hem. A two-layer LSTM captures long-range campaign structure, while a firs t-order Markov model estimated from 8,437 real-world intrusion sequences s upplies short-range transition priors. The combined model predicts adversa ry progression at the technique level with 86% next-step accuracy. Constra ined beam search then expands observed prefixes into 26,051 risk-ranked co ntinuations, each scored on a continuous 0 to 10 scale that combines explo itation likelihood, defensive observability from D3FEND coverage, and OCTA VE organizational impact. The second half turns that foundation into decis ion theory. We map every parameter of the ARA-OSID (Adversarial Risk Analy sis for Open Set Intrusion Detection) utility functions to a specific, aud itable ATT&CK field. On the attacker side these are effort, detection prob ability, resource cost, and benefit. On the defender side they are threat probability, false negative cost, false positive cost, model repair cost, and operating cost. The sources are required permissions, sub-technique co unts, D3FEND countermeasure coverage, kill-chain position, technique usage frequency across 143 documented threat groups, and campaign severity unde r CISA's National Cyber Incident Scoring System. Attacker and defender exp ected utilities are computed by Monte Carlo integration under risk-averse preferences, validated against NCISS campaign severity, and tested through a sensitivity analysis over the few weights that remain configurable. The result is a reproducible path from public threat intelligence to a defens ible detection posture, where the chosen configuration is justified by evi dence about how adversaries actually behave instead of by assumed paramete r values. For further information please contact Dr. Gokhan Kul at gkul@um assd.edu.Ìý\nEvent page: /events/cms/8-11-26-from-th reat-intelligence-to-decision-theory.php\nEvent link: https://teams.micros oft.com/meet/221432094573069?p=dUB81Fqp8iILmMc0o8 X-ALT-DESC;FMTTYPE=text/html:

ÌÇÐÄlogoÈë¿Ú

Thesis Advisor: Dr. Gokhan Kul - Computer & Information Science
Ìý
Committee Members:Ìý
Dr . Debarun Das - Computer & Information Science
Dr. Ashokkumar Patel - Computer & Information Science
Ìý
Abstract:

\n

Adversarial Risk Analysis (ARA) offers a decision-theoretic alternative to game-theor etic models of network defense. Instead of assuming that attacker and defe nder know each other's payoffs and settle into an equilibrium\, the defend er reasons under subjective uncertainty about adversary behavior and picks up the security posture that maximizes expected utility. Adoption has bee n limited for one narrow reason: the utility functions at the center of th e analysis are assumed rather than measured. This thesis derives them from published cyber threat intelligence.
The first half builds the empir ical foundation. We process MITRE ATT&CK v16 into 4\,849 tactic-ordered ca mpaign chains from 33 documented campaigns and train a hybrid forecasting model on them. A two-layer LSTM captures long-range campaign structure\, w hile a first-order Markov model estimated from 8\,437 real-world intrusion sequences supplies short-range transition priors. The combined model pred icts adversary progression at the technique level with 86% next-step accur acy. Constrained beam search then expands observed prefixes into 26\,051 r isk-ranked continuations\, each scored on a continuous 0 to 10 scale that combines exploitation likelihood\, defensive observability from D3FEND cov erage\, and OCTAVE organizational impact.

\n

The second half turns th at foundation into decision theory. We map every parameter of the ARA-OSID (Adversarial Risk Analysis for Open Set Intrusion Detection) utility func tions to a specific\, auditable ATT&CK field. On the attacker side these a re effort\, detection probability\, resource cost\, and benefit. On the de fender side they are threat probability\, false negative cost\, false posi tive cost\, model repair cost\, and operating cost. The sources are requir ed permissions\, sub-technique counts\, D3FEND countermeasure coverage\, k ill-chain position\, technique usage frequency across 143 documented threa t groups\, and campaign severity under CISA's National Cyber Incident Scor ing System. Attacker and defender expected utilities are computed by Monte Carlo integration under risk-averse preferences\, validated against NCISS campaign severity\, and tested through a sensitivity analysis over the fe w weights that remain configurable.

\n

The result is a reproducible p ath from public threat intelligence to a defensible detection posture\, wh ere the chosen configuration is justified by evidence about how adversarie s actually behave instead of by assumed parameter values.

\n

For furt her information please contact Dr. Gokhan Kul at gkul@umassd.edu.Ìý

Event page: /events/cms/8- 11-26-from-threat-intelligence-to-decision-theory.php
Event link: < a href="https://teams.microsoft.com/meet/221432094573069?p=dUB81Fqp8iILmMc 0o8">https://teams.microsoft.com/meet/221432094573069?p=dUB81Fqp8iILmMc0o8

DTSTAMP:20260726T135147 DTSTART;TZID=America/New_York:20260811T140000 DTEND;TZID=America/New_York:20260811T150000 LOCATION:Online - Microsoft Teams SUMMARY;LANGUAGE=en-us:From Threat Intelligence to Decision Theory: Empiric ally Grounded Utility Functions for Adversarial Risk Analysis in Network I ntrusion Detection UID:5ebee3adb38c8d4efab22226336acf62@www.umassd.edu END:VEVENT END:VCALENDAR