DSpace Repository

A Quantitative Security Risk Analysis Framework for Modelling and Analyzing Advanced Persistent Threats

Show simple item record

dc.contributor.author Kumar, Rajesh
dc.date.accessioned 2023-01-09T07:15:22Z
dc.date.available 2023-01-09T07:15:22Z
dc.date.issued 2021-02
dc.identifier.uri https://link.springer.com/chapter/10.1007/978-3-030-70881-8_3
dc.identifier.uri http://dspace.bits-pilani.ac.in:8080/xmlui/handle/123456789/8391
dc.description.abstract Advanced persistent threats (APTs) are different from other computer-based attacks in their target selection, attack technique, and malicious motive. Distinct from script kiddie attacks, these attacks target critical systems to inflict maximum damage, such as to stall critical industrial processes. Standard defenses against APT attack is to deploy security mechanisms that are typically reminiscent of enterprise defense systems such as firewalls, intrusion detection systems, etc. However, given the nature and attack potential of APT attacks, one cannot rely on these security mechanisms alone as they are susceptible to failure, false alarms, and interfere with usability. A yet another problem is to decide on which mechanisms to deploy and at which points to offer maximum coverage against attacks. We believe, given the unique characteristics of APT attacks, one needs a robust and layered defense to protect against APT by timely detection, prevention, mitigation, and emergency plan. One such objective way to determine the countermeasures’ efficacy is by modeling and simulating attack behaviour. In this paper, we propose a two-layer framework to analyze the APT attacks. At the top is the domain model of the Enhanced cyber kill chain. We use it to capture the attack phases, techniques, and processes. The bottom layer is the analytic layer of stochastic timed automata derived from the domain model. Key metrics are obtained using a state-of-the-art statistical model - checking techniques. We argue that such a timed analysis can be used to improve the security posture by putting countermeasures at appropriate positions. en_US
dc.language.iso en en_US
dc.publisher Springer en_US
dc.subject Computer Science en_US
dc.subject Attack trees en_US
dc.subject Security analysis en_US
dc.subject Parallel and sequential execution en_US
dc.title A Quantitative Security Risk Analysis Framework for Modelling and Analyzing Advanced Persistent Threats en_US
dc.type Article en_US


Files in this item

Files Size Format View

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account