Cyber-attacks are becoming more sophisticated and complex. This project aimed to improve the existing endpoint monitoring using artificial intelligence by moving from flat, event-based models to hierarchical multi-agent models. A “semantic” analysis (log lines are grounded within knowledge about the IT infrastructure) leads to behavioural information to support Security Operation Centre (SOC) analysts. This information can also be used to spot anomalies.
CAsK: Applying distributed multi-agent models for the detection of cyber attacks across the kill chain