From Threat Intelligence to Decision Theory: Empirically Grounded Utility Functions for Adversarial Risk Analysis in Network Intrusion Detection
Online - Microsoft Teams
Dr. Gokhan Kul
gkul@umassd.edu
https://teams.microsoft.com/meet/221432094573069?p=dUB81Fqp8iILmMc0o8
Thesis Advisor: Dr. Gokhan Kul - Computer & Information Science
Committee Members:
Dr. Debarun Das - Computer & Information Science
Dr. Ashokkumar Patel - Computer & Information Science
Abstract:
Adversarial Risk Analysis (ARA) offers a decision-theoretic alternative to game-theoretic models of network defense. Instead of assuming that attacker and defender know each other's payoffs and settle into an equilibrium, the defender reasons under subjective uncertainty about adversary behavior and picks up the security posture that maximizes expected utility. Adoption has been limited for one narrow reason: the utility functions at the center of the analysis are assumed rather than measured. This thesis derives them from published cyber threat intelligence.
The first half builds the empirical foundation. We process MITRE ATT&CK v16 into 4,849 tactic-ordered campaign chains from 33 documented campaigns and train a hybrid forecasting model on them. A two-layer LSTM captures long-range campaign structure, while a first-order Markov model estimated from 8,437 real-world intrusion sequences supplies short-range transition priors. The combined model predicts adversary progression at the technique level with 86% next-step accuracy. Constrained beam search then expands observed prefixes into 26,051 risk-ranked continuations, each scored on a continuous 0 to 10 scale that combines exploitation likelihood, defensive observability from D3FEND coverage, and OCTAVE organizational impact.
The second half turns that foundation into decision theory. We map every parameter of the ARA-OSID (Adversarial Risk Analysis for Open Set Intrusion Detection) utility functions to a specific, auditable ATT&CK field. On the attacker side these are effort, detection probability, resource cost, and benefit. On the defender side they are threat probability, false negative cost, false positive cost, model repair cost, and operating cost. The sources are required permissions, sub-technique counts, D3FEND countermeasure coverage, kill-chain position, technique usage frequency across 143 documented threat groups, and campaign severity under CISA's National Cyber Incident Scoring System. Attacker and defender expected utilities are computed by Monte Carlo integration under risk-averse preferences, validated against NCISS campaign severity, and tested through a sensitivity analysis over the few weights that remain configurable.
The result is a reproducible path from public threat intelligence to a defensible detection posture, where the chosen configuration is justified by evidence about how adversaries actually behave instead of by assumed parameter values.
For further information please contact Dr. Gokhan Kul at gkul@umassd.edu.