Fronesis: Digital Forensics-Based Early Detection of Ongoing Cyber-Attacks

Authors

  • Paka Akhila
  • Mr. K Vijay

Keywords:

MITRE ATT&CK

Abstract

Traditional attack detection approaches utilize predefined databases of known signatures about
already-seen tools and malicious activities observed in past cyber-attacks to detect future
attacks. More sophisticated approaches apply machine learning to detect abnormal behavior.
Nevertheless, a growing number of successful attacks and the increasing ingenuity of attackers
prove that these approaches are insufficient. This paper introduces an approach for digital
forensics-based early detection of ongoing cyber-attacks called Fronesis. The approach
combines ontological reasoning with the MITRE ATT&CK framework, the Cyber Kill Chain
model, and the digital artifacts acquired continuously from the monitored computer system.
Fronesis examines the collected digital artifacts by applying rule based reasoning on the
Fronesis cyber-attack detection ontology to identify traces of adversarial techniques. The
identified techniques are correlated to tactics, which are then mapped to corresponding phases
of the Cyber Kill Chain model, resulting in the detection of an ongoing cyber-attack. Finally,
the proposed approach is demonstrated through an email phishing attack scenario.

Downloads

Published

2025-08-14

How to Cite

Paka Akhila, & Mr. K Vijay. (2025). Fronesis: Digital Forensics-Based Early Detection of Ongoing Cyber-Attacks. Utilitas Mathematica, 122(Special Issue-1), 1240–1244. Retrieved from https://utilitasmathematica.com/index.php/Index/article/view/2644

Citation Check

Most read articles by the same author(s)

Obs.: This plugin requires at least one statistics/report plugin to be enabled. If your statistics plugins provide more than one metric then please also select a main metric on the admin's site settings page and/or on the journal manager's settings pages.