BEGIN:VCALENDAR
VERSION:2.0
X-WR-CALNAME:EventsCalendar
PRODID:-//hacksw/handcal//NONSGML v1.0//EN
CALSCALE:GREGORIAN
BEGIN:VTIMEZONE
TZID:America/New_York
LAST-MODIFIED:20240422T053451Z
TZURL:https://www.tzurl.org/zoneinfo-outlook/America/New_York
X-LIC-LOCATION:America/New_York
BEGIN:DAYLIGHT
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
DTSTART:19700308T020000
RRULE:FREQ=YEARLY;BYMONTH=3;BYDAY=2SU
END:DAYLIGHT
BEGIN:STANDARD
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
DTSTART:19701101T020000
RRULE:FREQ=YEARLY;BYMONTH=11;BYDAY=1SU
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
CATEGORIES:College of Arts and Sciences,College of Engineering,Thesis/Disse
 rtations
DESCRIPTION:Thesis Advisor: Dr. Gokhan Kul - Computer & Information Science
  Committee Members: Dr. Debarun Das - Computer & Information ScienceDr. 
 Ashokkumar Patel - Computer & Information Science Abstract: Adversarial R
 isk Analysis (ARA) offers a decision-theoretic alternative to game-theoret
 ic models of network defense. Instead of assuming that attacker and defend
 er know each other's payoffs and settle into an equilibrium, the defender 
 reasons under subjective uncertainty about adversary behavior and picks up
  the security posture that maximizes expected utility. Adoption has been l
 imited for one narrow reason: the utility functions at the center of the a
 nalysis are assumed rather than measured. This thesis derives them from pu
 blished cyber threat intelligence.The first half builds the empirical foun
 dation. We process MITRE ATT&CK v16 into 4,849 tactic-ordered campaign cha
 ins from 33 documented campaigns and train a hybrid forecasting model on t
 hem. A two-layer LSTM captures long-range campaign structure, while a firs
 t-order Markov model estimated from 8,437 real-world intrusion sequences s
 upplies short-range transition priors. The combined model predicts adversa
 ry progression at the technique level with 86% next-step accuracy. Constra
 ined beam search then expands observed prefixes into 26,051 risk-ranked co
 ntinuations, each scored on a continuous 0 to 10 scale that combines explo
 itation likelihood, defensive observability from D3FEND coverage, and OCTA
 VE organizational impact. The second half turns that foundation into decis
 ion theory. We map every parameter of the ARA-OSID (Adversarial Risk Analy
 sis for Open Set Intrusion Detection) utility functions to a specific, aud
 itable ATT&CK field. On the attacker side these are effort, detection prob
 ability, resource cost, and benefit. On the defender side they are threat 
 probability, false negative cost, false positive cost, model repair cost, 
 and operating cost. The sources are required permissions, sub-technique co
 unts, D3FEND countermeasure coverage, kill-chain position, technique usage
  frequency across 143 documented threat groups, and campaign severity unde
 r CISA's National Cyber Incident Scoring System. Attacker and defender exp
 ected utilities are computed by Monte Carlo integration under risk-averse 
 preferences, validated against NCISS campaign severity, and tested through
  a sensitivity analysis over the few weights that remain configurable. The
  result is a reproducible path from public threat intelligence to a defens
 ible detection posture, where the chosen configuration is justified by evi
 dence about how adversaries actually behave instead of by assumed paramete
 r values. For further information please contact Dr. Gokhan Kul at gkul@um
 assd.edu. \nEvent page: https://www.umassd.edu/events/cms/8-11-26-from-th
 reat-intelligence-to-decision-theory.php\nEvent link: https://teams.micros
 oft.com/meet/221432094573069?p=dUB81Fqp8iILmMc0o8
X-ALT-DESC;FMTTYPE=text/html:<html><body><p>Thesis Advisor: Dr. Gokhan Kul 
 - Computer & Information Science<br /> <br />Committee Members: <br />Dr
 . Debarun Das - Computer & Information Science<br />Dr. Ashokkumar Patel -
  Computer & Information Science<br /> <br />Abstract:</p>\n<p>Adversarial
  Risk Analysis (ARA) offers a decision-theoretic alternative to game-theor
 etic models of network defense. Instead of assuming that attacker and defe
 nder know each other's payoffs and settle into an equilibrium\, the defend
 er reasons under subjective uncertainty about adversary behavior and picks
  up the security posture that maximizes expected utility. Adoption has bee
 n limited for one narrow reason: the utility functions at the center of th
 e analysis are assumed rather than measured. This thesis derives them from
  published cyber threat intelligence.<br />The first half builds the empir
 ical foundation. We process MITRE ATT&CK v16 into 4\,849 tactic-ordered ca
 mpaign chains from 33 documented campaigns and train a hybrid forecasting 
 model on them. A two-layer LSTM captures long-range campaign structure\, w
 hile a first-order Markov model estimated from 8\,437 real-world intrusion
  sequences supplies short-range transition priors. The combined model pred
 icts adversary progression at the technique level with 86% next-step accur
 acy. Constrained beam search then expands observed prefixes into 26\,051 r
 isk-ranked continuations\, each scored on a continuous 0 to 10 scale that 
 combines exploitation likelihood\, defensive observability from D3FEND cov
 erage\, and OCTAVE organizational impact.</p>\n<p>The second half turns th
 at foundation into decision theory. We map every parameter of the ARA-OSID
  (Adversarial Risk Analysis for Open Set Intrusion Detection) utility func
 tions to a specific\, auditable ATT&CK field. On the attacker side these a
 re effort\, detection probability\, resource cost\, and benefit. On the de
 fender side they are threat probability\, false negative cost\, false posi
 tive cost\, model repair cost\, and operating cost. The sources are requir
 ed permissions\, sub-technique counts\, D3FEND countermeasure coverage\, k
 ill-chain position\, technique usage frequency across 143 documented threa
 t groups\, and campaign severity under CISA's National Cyber Incident Scor
 ing System. Attacker and defender expected utilities are computed by Monte
  Carlo integration under risk-averse preferences\, validated against NCISS
  campaign severity\, and tested through a sensitivity analysis over the fe
 w weights that remain configurable.</p>\n<p>The result is a reproducible p
 ath from public threat intelligence to a defensible detection posture\, wh
 ere the chosen configuration is justified by evidence about how adversarie
 s actually behave instead of by assumed parameter values.</p>\n<p>For furt
 her information please contact Dr. Gokhan Kul at gkul@umassd.edu. </p><p>
 Event page: <a href="https://www.umassd.edu/events/cms/8-11-26-from-threat
 -intelligence-to-decision-theory.php">https://www.umassd.edu/events/cms/8-
 11-26-from-threat-intelligence-to-decision-theory.php</a><br>Event link: <
 a href="https://teams.microsoft.com/meet/221432094573069?p=dUB81Fqp8iILmMc
 0o8">https://teams.microsoft.com/meet/221432094573069?p=dUB81Fqp8iILmMc0o8
 </a></p></body></html>
DTSTAMP:20260723T124044
DTSTART;TZID=America/New_York:20260811T140000
DTEND;TZID=America/New_York:20260811T150000
LOCATION:Online - Microsoft Teams
SUMMARY;LANGUAGE=en-us:From Threat Intelligence to Decision Theory: Empiric
 ally Grounded Utility Functions for Adversarial Risk Analysis in Network I
 ntrusion Detection
UID:a4f8cd108dd1329f3f76b813acc6500a@www.umassd.edu
END:VEVENT
END:VCALENDAR
