Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Huang, Zequan, Robin, Jacques, Herbaut, Nicolas, Rabah, Nourhène Ben, Grand, Bénédicte Le
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913944397938688
author Huang, Zequan
Robin, Jacques
Herbaut, Nicolas
Rabah, Nourhène Ben
Grand, Bénédicte Le
author_facet Huang, Zequan
Robin, Jacques
Herbaut, Nicolas
Rabah, Nourhène Ben
Grand, Bénédicte Le
contents Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms.
format Preprint
id arxiv_https___arxiv_org_abs_2507_12061
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response
Huang, Zequan
Robin, Jacques
Herbaut, Nicolas
Rabah, Nourhène Ben
Grand, Bénédicte Le
Cryptography and Security
Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms.
title Toward an Intent-Based and Ontology-Driven Autonomic Security Response in Security Orchestration Automation and Response
topic Cryptography and Security
url https://arxiv.org/abs/2507.12061