vix.ing · top · new · best · stats · spec

Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response

2025/07/16 by Zhongzi Huang, Huang, Zequan, Jacques Robin +7 · 2 citations
Computer Science · #Advanced Malware Detection Techniques #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information and Cyber Security #Network Security and Intrusion Detection

paper · pdf · doi:10.48550/arxiv.2507.12061

openalex publication_date 2025/07/16 · openalex created_date 2025/10/14 · openalex updated_date 2026/07/28

Abstract

Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms.

Citations

Cited by

Related