• DocumentCode
    630134
  • Title

    How to use experience in cyber analysis: An analytical reasoning support system

  • Author

    Chen Zhong ; Kirubakaran, Deepak S. ; Yen, J. ; Peng Liu ; Hutchinson, Seth ; Cam, Hasan

  • Author_Institution
    Pennsylvania State Univ., State College, PA, USA
  • fYear
    2013
  • fDate
    4-7 June 2013
  • Firstpage
    263
  • Lastpage
    265
  • Abstract
    Cyber analysis is a difficult task for analysts due to huge amounts of noise-abundant monitoring data and increasing complexity of the reasoning tasks. Therefore, experience from experts can provide guidance for analysts´ analytical reasoning and contribute to training. Despite its great potential benefits, experience has not been effectively leveraged in the existing reasoning support systems due to the difficulty of elicitation and reuse. To fill the gap, we propose an experience-aided reasoning support system which can automatically capture experts´ experi-ence and subsequently guide the novices´ reasoning in a step-by-step manner. Drawing on cognitive theory, we model experience as a reasoning process involving “actions”, “observations”, and “hypotheses”. Computability and adaptability are the compar-ative advantages of this model: the “hypotheses” capture analysts´ internal mental reasoning as a black box, while the “actions” and “observations” formally representing the external context and analysts´ evidence exploration activities. This paper demonstrates how this system, built on this experience model, can capture and utilize experience effectively.
  • Keywords
    inference mechanisms; security of data; Cyber analysis; analytical reasoning support system; cognitive theory; experience-aided reasoning support system; mental reasoning; noise abundant monitoring data; reasoning process; Adaptation models; Analytical models; Cognition; Computational modeling; Context; Monitoring; Servers; Analytical Reasoning; Experience-aided;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Intelligence and Security Informatics (ISI), 2013 IEEE International Conference on
  • Conference_Location
    Seattle, WA
  • Print_ISBN
    978-1-4673-6214-6
  • Type

    conf

  • DOI
    10.1109/ISI.2013.6578832
  • Filename
    6578832