Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866913944397938688 |
|---|---|
| author | Huang, Zequan Robin, Jacques Herbaut, Nicolas Rabah, Nourhène Ben Grand, Bénédicte Le |
| author_facet | Huang, Zequan Robin, Jacques Herbaut, Nicolas Rabah, Nourhène Ben Grand, Bénédicte Le |
| contents | Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2507_12061 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response Huang, Zequan Robin, Jacques Herbaut, Nicolas Rabah, Nourhène Ben Grand, Bénédicte Le Cryptography and Security Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms. |
| title | Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2507.12061 |