• DocumentCode
    665593
  • Title

    Intended effects of cyber resiliency techniques on adversary activities

  • Author

    Bodeau, Deborah ; Graubart, Richard

  • Author_Institution
    MITRE Corp., Bedford, MA, USA
  • fYear
    2013
  • fDate
    12-14 Nov. 2013
  • Firstpage
    7
  • Lastpage
    11
  • Abstract
    Evidence and analysis are needed to determine whether, how, and to what extent architectural and operational decisions have an effect on cyber adversary behavior. This is particularly the case for cyber resiliency techniques, which are relatively new compared with conventional perimeter defenses and intrusion detection techniques. In this paper, we propose a vocabulary for describing effects on cyber adversaries. The vocabulary is compatible with existing terminology for Information Operations (IO), as well as for such modeling and analysis techniques as Red Team analysis, game-theoretic modeling, attack tree and attack graph modeling, and analysis based on the cyber attack lifecycle. We use this vocabulary to map cyber resiliency techniques to the different phases of a cyber campaign. This use of the vocabulary enables the identification of measures of effectiveness (MOEs) or metrics for effects on adversary activities. The mapping also illuminates how cyber resiliency techniques apply differently to address various adversary activities, and thus provides a basis for identifying effective combinations of techniques.
  • Keywords
    game theory; security of data; trees (mathematics); MOE identification; adversary activities; architectural decisions; attack graph modeling; attack tree modeling; cyber adversary behavior; cyber attack lifecycle; cyber campaign; cyber resiliency techniques; game-theoretic modeling; information operations; intrusion detection techniques; measures-of-effectiveness; operational decisions; perimeter defenses; red team analysis; Analytical models; Delays; Dynamic scheduling; Resilience; Security; Vocabulary; advanced persistent threat; computer security; cyber security; information security; mission assurance; resilience;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Technologies for Homeland Security (HST), 2013 IEEE International Conference on
  • Conference_Location
    Waltham, MA
  • Print_ISBN
    978-1-4799-3963-3
  • Type

    conf

  • DOI
    10.1109/THS.2013.6698967
  • Filename
    6698967