• DocumentCode
    263541
  • Title

    The “triptych of cyber security”: A classifi cation of active cyber defence

  • Author

    Dewar, Robert S.

  • Author_Institution
    Dept. of Politics, Univ. of Glasgow, Glasgow, UK
  • fYear
    2014
  • fDate
    3-6 June 2014
  • Firstpage
    7
  • Lastpage
    21
  • Abstract
    In the field of cyber security, ill-defined concepts and inconsistently applied terminology are further complicating an already complex issue. This causes difficulties for policy-makers, strategists and academics. Using national cyber security strategies to support current literature, this paper undertakes three tasks with the goal of classifying and defining terms to begin the development of a lexicon of cyber security terminology. The first task is to offer for consideration a definition of “active cyber defence” (ACD). This definition is based upon a number of characteristics identified in current academic and policy literature. ACD is defined here as the proactive detection, analysis and mitigation of network security breaches in real-time combined with the use of aggressive countermeasures deployed outside the victim network. Once defined, ACD is contextualised alongside two further approaches to cyber defence and security. These are fortified and resilient cyber defence, predicated upon defensive perimeters and ensuring continuity of services respectively. This contextualisation is postulated in order to provide more clarity to non-active cyber defence measures than is offered by the commonly used term “passive cyber defence”. Finally, it is shown that these three approaches to cyber defence and security are neither mutually exclusive nor applied independently of one another. Rather they operate in a complementary triptych of policy approaches to achieving cyber security.
  • Keywords
    pattern classification; security of data; ACD; active cyber defence classification; aggressive countermeasures; cyber security strategy; cyber security terminology; defensive perimeters; network security breaches; passive cyber defence; service continuity; Computer security; Cyberspace; Internet; Real-time systems; Software; Terminology; active cyber defence; classifi cation; cyber security; defi nition; lexicon; resilience; triptych;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cyber Conflict (CyCon 2014), 2014 6th International Conference On
  • Conference_Location
    Tallinn
  • ISSN
    2325-5366
  • Print_ISBN
    978-9949-9544-0-7
  • Type

    conf

  • DOI
    10.1109/CYCON.2014.6916392
  • Filename
    6916392