简介
It is generally accepted that all cyber attacks can not be prevented, and it is therefore necessary to have the ability to detect and respond to cyber attacks. Both connectionist and symbolic approaches are currently being employed for this purpose, but far less work has been done on the intersection of the two. This paper argues that the cyber security domain holds significant potential for applying neurosymbolic artificial intelligence (AI). We identify a set of challenges faced in cyber security today, and from this, we propose a set of neurosymbolic use cases that can help address the challenges. Feasibility is demonstrated through multiple experiments that apply neurosymbolic AI to cyber security. We find a significant overlap between the challenges in cyber security and the promises
代表成果
- Scientific articles and book chapters
- Chetwyn, Robert Andrew & Erdodi, Laszlo Tibor (2026). Using Indicators of Behavior to Contextualise SQL Injection Attacks. Acta Polytechnica Hungarica (APH). ISSN 1785-8860. 23(5), p. 67–86. doi: 10.12700/APH.23.5.2026.5.4. Full text in Research Archive
- Eckhoff, Magnus Wiik; Halvorsen, Jonas; Hansen, Bjørn Jervell; Eian, Martin; Mavroeidis, Vasileios & Chetwyn, Robert Andrew [Show all 8 contributors for this article] (2025). Experimenting with Neurosymbolic Artificial Intelligence for Defending Against Cyber Attacks. Neurosymbolic Artificial Intelligence. ISSN 2949-8732. 1. doi: 10.1177/29498732251377352. Full text in Research Archive Show summary It is generally accepted that all cyber attacks can not be prevented, and it is therefore necessary to have the ability to detect and respond to cyber attacks. Both connectionist and symbolic approaches are currently being employed for this purpose, but far less work has been done on the intersection of the two. This paper argues that the cyber security domain holds significant potential for applying neurosymbolic artificial intelligence (AI). We identify a set of challenges faced in cyber security today, and from this, we propose a set of neurosymbolic use cases that can help address the challenges. Feasibility is demonstrated through multiple experiments that apply neurosymbolic AI to cyber security. We find a significant overlap between the challenges in cyber security and the promises of neurosymbolic techniques, making it an interesting research direction for both the neurosymbolic AI and cyber security communities. This paper is an extended version of a paper published at the NeSy 2024 conference ( Grov et al., 2024 ). The main additional contributions are further experimental evidence for our hypothesis that NeSy offers real benefits in this domain and a more in-depth treatment of knowledge graphs for cyber security.
- Chetwyn, Robert Andrew & Erdodi, Laszlo Tibor (2023). Towards Dynamic Capture-The-Flag Training Environments For Reinforcement Learning Offensive Security Agents. In Tsumoto, Shusaku; Ohsawa, Yukio; Chen, Lei; Poel, Dirk Van den; Hu, Xiaohua; Motomura, Yoichi; Takagi, Takuya; Wu, Lingfei; Xie, Ying; Abe, Akihiro & Raghavan, Vijay (Ed.), 2022 IEEE International Conference on Big Data. IEEE (Institute of Electrical and Electronics Engineers). ISSN 9781665480451. doi: 10.1109/BigData55660.2022.10020389. Full text in Research Archive
- Chetwyn, Robert Andrew & Erdodi, Laszlo (2021). Cheat Detection In Cyber Security Capture The Flag Games - An Automated Cyber Threat Hunting Approach. CEUR Workshop Proceedings. Vol-3056, p. 175–190. Full text in Research Archive
- Chetwyn, Robert Andrew (2026). Semi-Automated Identification of Threat Actor Behavior. Universitetet i Oslo. Full text in Research Archive Show summary Threat hunting is the work of actively investigating a network for signs of attackers. It can be approached in many ways, but these approaches share a common need: analysts must piece together meaning from large volumes of scattered, low-level data, often relying on personal expertise and painstaking manual work. A common starting clue is an "indicator of compromise," such as a suspicious file or internet address. But these clues are easy for an attacker to change, and on their own they say little about what an intruder is actually trying to do. This thesis adds the missing context. Instead of focusing on isolated clues, it describes attacker behaviour - what the adversary is trying to achieve and captures it in a structured knowledge graph. Using semantic-web technology, it links many small events into meaningful behavioural patterns and reasons about how they connect, with explanations a human can follow. The result gives threat hunters richer, semi-automated context: they can see not just what happened, but why and how supporting better-reasoned investigations while keeping the human analyst in charge.
数据校验于 9/6/2026数据来源