Go to:
Logótipo
Comuta visibilidade da coluna esquerda
Você está em: Start > Publications > View > A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 With New Scoring and Data Sources
Publication

Publications

A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 With New Scoring and Data Sources

Title
A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 With New Scoring and Data Sources
Type
Article in International Scientific Journal
Year
2025
Authors
Freitas, T
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Novo, C
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Dutra, I
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Soares, J
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Shariati, B
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Martins, R
(Author)
Other
The person does not belong to the institution. The person does not belong to the institution. The person does not belong to the institution. Without AUTHENTICUS Without ORCID
Journal
ISSN: 0038-0644
Publisher: Wiley-Blackwell
Scientific classification
CORDIS: Technological sciences > Engineering > Computer engineering
FOS: Engineering and technology > Electrical engineering, Electronic engineering, Information engineering
Other information
Authenticus ID: P-019-X93
Abstract (EN): <jats:title>ABSTRACT</jats:title><jats:sec><jats:title>Background</jats:title><jats:p>Intrusion Tolerant Systems (ITS) aim to maintain system security despite adversarial presence by limiting the impact of successful attacks. Current ITS risk managers rely heavily on public databases like NVD and Exploit DB, which suffer from long delays in vulnerability evaluation, reducing system responsiveness.</jats:p></jats:sec><jats:sec><jats:title>Objective</jats:title><jats:p>This work extends the HAL 9000 Risk Manager to integrate additional real¿time threat intelligence sources and employ machine learning techniques to automatically predict and reassess vulnerability risk scores, addressing limitations of existing solutions.</jats:p></jats:sec><jats:sec><jats:title>Methods</jats:title><jats:p>A custom¿built scraper collects diverse cybersecurity data from multiple Open Source Intelligence (OSINT) platforms, such as NVD, CVE, AlienVault OTX, and OSV. HAL 9000 uses machine learning models for CVE score prediction, vulnerability clustering through scalable algorithms, and reassessment incorporating exploit likelihood and patch availability to dynamically evaluate system configurations.</jats:p></jats:sec><jats:sec><jats:title>Results</jats:title><jats:p>Integration of newly scraped data significantly enhances the risk management capabilities, enabling faster detection and mitigation of emerging vulnerabilities with improved resilience and security. Experiments show HAL 9000 provides lower risk and more resilient configurations compared to prior methods while maintaining scalability and automation.</jats:p></jats:sec><jats:sec><jats:title>Conclusions</jats:title><jats:p>The proposed enhancements position HAL 9000 as a next¿generation autonomous Risk Manager capable of effectively incorporating diverse intelligence sources and machine learning to improve ITS security posture in dynamic threat environments. Future work includes expanding data sources, addressing misinformation risks, and real¿world deployments.</jats:p></jats:sec>
Language: English
Type (Professor's evaluation): Scientific
Documents
We could not find any documents associated to the publication.
Related Publications

Of the same journal

Toward characterizing HTML defects on the Web (2018)
Article in International Scientific Journal
Joaquim Mendes; Laranjeiro, N; Vieira, M
Thread- and process-based implementations of the pSystem parallel programming environment (1997)
Article in International Scientific Journal
Lopes, LMB; Silva, FMA
Prioritizing Tests for Software Fault Localization (2011)
Article in International Scientific Journal
Alberto Gonzalez-Sanchez; Eric Piel; Rui Abreu; Hans-Gerhard Gross; Arjan J.C. van Gemund
Prioritizing tests for software fault diagnosis (2011)
Article in International Scientific Journal
Alberto Gonzalez Sanchez; Eric Piel; Rui Abreu; Hans Gerhard Gross; Arjan J C van Gemund
Performance-driven instrumentation and mapping strategies using the LARA aspect-oriented programming approach (2016)
Article in International Scientific Journal
João M. P. Cardoso; Coutinho, JGF; Carvalho, T; Diniz, PC; Petrov, Z; Luk, W; Goncalves, F

See all (11)

Recommend this page Top
Copyright 1996-2025 © Faculdade de Direito da Universidade do Porto  I Terms and Conditions  I Acessibility  I Index A-Z
Page created on: 2025-09-05 at 13:49:55 | Privacy Policy | Personal Data Protection Policy | Whistleblowing