🤖 AI Summary
Current SOAR platforms struggle to rapidly adapt to dynamic cyberattacks due to the absence of intent-driven, ontology-supported autonomous response mechanisms. To address this, we propose an ontology-driven security intent modeling and autonomous response integration method. Leveraging the MITRE-D3FEND ontology, we establish a unified security intent definition framework and a two-tier autonomous architecture—comprising an intent parsing layer and a decision-execution layer—to ensure semantically consistent mapping from high-level security intents to executable response actions. Our approach integrates intent-driven networking, hierarchical autonomous control, and decision-theoretic modeling to enable context-aware, multi-level response orchestration. Experimental evaluation demonstrates the feasibility of the proposed mechanism within next-generation SOAR platforms, significantly improving threat handling adaptability, semantic consistency across intent and action, and sustained autonomous response capability.
📝 Abstract
Modern Security Orchestration, Automation, and Response (SOAR) platforms must rapidly adapt to continuously evolving cyber attacks. Intent-Based Networking has emerged as a promising paradigm for cyber attack mitigation through high-level declarative intents, which offer greater flexibility and persistency than procedural actions. In this paper, we bridge the gap between two active research directions: Intent-Based Cyber Defense and Autonomic Cyber Defense, by proposing a unified, ontology-driven security intent definition leveraging the MITRE-D3FEND cybersecurity ontology. We also propose a general two-tiered methodology for integrating such security intents into decision-theoretic Autonomic Cyber Defense systems, enabling hierarchical and context-aware automated response capabilities. The practicality of our approach is demonstrated through a concrete use case, showcasing its integration within next-generation Security Orchestration, Automation, and Response platforms.