An overview of the parallax BattleMind v1.5 for computer network defence

  • Authors:
  • Duncan Grove;Alex Murray;Damien Gerhardy;Benjamin Turnbull;Troy Tobin;Christopher Moir

  • Affiliations:
  • Defence Science Technology Organisation, Edinburgh, South Australia;Defence Science Technology Organisation, Edinburgh, South Australia;Defence Science Technology Organisation, Edinburgh, South Australia;Defence Science Technology Organisation, Edinburgh, South Australia;Defence Science Technology Organisation, Edinburgh, South Australia;Defence Science Technology Organisation, Edinburgh, South Australia

  • Venue:
  • AISC '13 Proceedings of the Eleventh Australasian Information Security Conference - Volume 138
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

BattleMind (BM) version 1.5 is the first of a series of Artificial Intelligence systems for semi-automatically understanding, planning and conducting Computer Network Defence. It makes use of a wide range of existing techniques including classification and feature extraction, semantic web technologies, data fusion, ontologies, first order predicate logic based forward and backward chained reasoning, hierarchical task network planning and supervised learning. Novel contributions of our work compared to other AI based CND tools are: (1) explicitly modelling people and organisations as well as computers and networks as part of the overall system, and elements of the business processes that link them; and (2) using a broad range of high level data sources rather than just traditional low level data sources such as packet capture.