Skip to content

D4.3 Report on data analysis and visualization methods

[featured_image]
  • Version
  • Download 8
  • File Size 1.44 MB
  • File Count 1
  • Create Date 29 de August de 2023
  • Last Updated 18 de July de 2024

D4.3 Report on data analysis and visualization methods

The current deliverable introduces the Thor Analytics module, an extension for the AI tools developed in WP4. The module offers two anomaly detection methods: Thor Analytics Σ, a signature-based system with conversational AI, and Thor Analytics λ, a cloud-based deep learning model with explainable AI for detecting malicious traffic. Thor Analytics Σ leverages a signature-based system, utilizing Indicators of Compromise (IOCs) from the THOR Cyber Threat Intelligence Platform (i.e., Thor-CTI). Unique from traditional systems, it integrates a conversational AI agent to automate threat detection from the THOR-IOC database, thus enabling enhanced user interactions and decision-making for system responses. Conversely, Thor Analytics λ employs a cloud-based deep learning model to classify and detect malicious network traffic through Machine Learning Operations (MLOps) practices. This approach also leverages an explainable AI framework, giving users clarity on alert justifications. A pivotal feature of the proposed method is the inclusion of conversational agents for a more intuitive data access and user experience, presenting insights in interactive formats, and facilitating user-directed system modifications. This report further outlines the project's background, relevant studies on explainable AI and details of both detection solutions.