kth.sePublikationer KTH
Ändra sökning
Länk till posten
Permanent länk

Direktlänk
Publikationer (4 of 4) Visa alla publikationer
Smitha Rani, B. S., Mukherjee, P. & Ekstedt, M. (2025). Modular Analysis of Attack Graphs for Smart Grid Security. In: Proceedings Information Systems Security - 21st International Conference, ICISS 2025: . Paper presented at Information Systems Security - 21st International Conference, ICISS 2025, Indore, India, December 16-20, 2025. Springer Nature
Öppna denna publikation i ny flik eller fönster >>Modular Analysis of Attack Graphs for Smart Grid Security
2025 (Engelska)Ingår i: Proceedings Information Systems Security - 21st International Conference, ICISS 2025, Springer Nature , 2025Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

A smart grid is a modern power network designed to monitor, manage, and optimise the flow of electricity. A cyber attack on such a critical system can disrupt services and pose significant risks to public safety and national infrastructure. Cyber attackers targeting critical infrastructures like smart grids often follow predictable patterns that can be modelled and analysed. Attack graphs reveal these potential multi-stage attack patterns, highlighting attacker reachability. However, due to the sheer number of paths and the large size of the graph, their analysis becomes computationally challenging. In this paper, a modular analysis of attack graphs is proposed to address this issue by decomposing the graphs into manageable clusters or communities. By representing each community as a single node, the complex graph is transformed into a high-level abstraction that is easier to interpret. Segregating large attack graphs into clusters enables efficient, time-bound analysis and ultimately aids in defense strategy formulation. 

Ort, förlag, år, upplaga, sidor
Springer Nature, 2025
Serie
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349 ; 16380
Nationell ämneskategori
Datavetenskap (datalogi)
Forskningsämne
Datalogi
Identifikatorer
urn:nbn:se:kth:diva-384660 (URN)10.1007/978-3-032-13714-2_29 (DOI)2-s2.0-105025349086 (Scopus ID)
Konferens
Information Systems Security - 21st International Conference, ICISS 2025, Indore, India, December 16-20, 2025
Anmärkning

Part of ISBN 978-3-032-13714-2

QC 20260706

Tillgänglig från: 2026-07-02 Skapad: 2026-07-02 Senast uppdaterad: 2026-07-06Bibliografiskt granskad
Ekstedt, M., Afzal, Z., Mukherjee, P., Hacks, S. & Lagerström, R. (2023). Yet another cybersecurity risk assessment framework. International Journal of Information Security, 22(6), 1713-1729
Öppna denna publikation i ny flik eller fönster >>Yet another cybersecurity risk assessment framework
Visa övriga...
2023 (Engelska)Ingår i: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 22, nr 6, s. 1713-1729Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

IT systems pervade our society more and more, and we become heavily dependent on them. At the same time, these systems are increasingly targeted in cyberattacks, making us vulnerable. Enterprise and cybersecurity responsibles face the problem of defining techniques that raise the level of security. They need to decide which mechanism provides the most efficient defense with limited resources. Basically, the risks need to be assessed to determine the best cost-to-benefit ratio. One way to achieve this is through threat modeling; however, threat modeling is not commonly used in the enterprise IT risk domain. Furthermore, the existing threat modeling methods have shortcomings. This paper introduces a metamodel-based approach named Yet Another Cybersecurity Risk Assessment Framework (Yacraf). Yacraf aims to enable comprehensive risk assessment for organizations with more decision support. The paper includes a risk calculation formalization and also an example showing how an organization can use and benefit from Yacraf.

Ort, förlag, år, upplaga, sidor
Springer Nature, 2023
Nyckelord
Attack tree, Enterprise IT risk, Risk assessment, Threat modeling
Nationell ämneskategori
Datavetenskap (datalogi) Datorsystem
Identifikatorer
urn:nbn:se:kth:diva-338542 (URN)10.1007/s10207-023-00713-y (DOI)001027329600001 ()2-s2.0-85164669184 (Scopus ID)
Anmärkning

QC 20231108

Tillgänglig från: 2023-11-08 Skapad: 2023-11-08 Senast uppdaterad: 2023-11-08Bibliografiskt granskad
Fahlander, P., Ekstedt, M., Mukherjee, P. & Dwivedi, A. K. (2022). Containment Strategy Formalism in a Probabilistic Threat Modelling Framework. In: Paolo Mori, Gabriele Lenzini, Steven Furnell (Ed.), Proceedings of the 8th international conference on information systems security and privacy (ICISSP): . Paper presented at 8th International Conference on Information Systems Security and Privacy (ICISSP), Virtual/Online, 9-11 February, 2022 (pp. 108-120). Scitepress, 1
Öppna denna publikation i ny flik eller fönster >>Containment Strategy Formalism in a Probabilistic Threat Modelling Framework
2022 (Engelska)Ingår i: Proceedings of the 8th international conference on information systems security and privacy (ICISSP) / [ed] Paolo Mori, Gabriele Lenzini, Steven Furnell, Scitepress , 2022, Vol. 1, s. 108-120Konferensbidrag, Publicerat paper (Refereegranskat)
Abstract [en]

Foreseeing, mitigating and preventing cyber-attacks is more important than ever before. Advances in the field of probabilistic threat modelling can help organisations understand their own resilience profile against cyber-attacks. Previous research has proposed MAL, a meta language for capturing the attack logic of a considered domain and running attack simulations in a model that depicts the defended IT-infrastructure. While this modality is already somewhat established for proposing general threat mitigation actions, less is known about how to model containment strategies in the event that penetration already has occurred. The problem is a fundamental gap between predominant threat models in cyber-security research and containment in the incident response lifecycle. This paper presents a solution to the problem by summarizing a methodology for reasoning about containment strategies in MAL-based threat models.

Ort, förlag, år, upplaga, sidor
Scitepress, 2022
Serie
Proceedings of the 8th International Conference on Information Systems Security and Privacy 2022, ISSN 2184-4356
Nyckelord
Threat Analysis, MAL, Containment strategies, Simulated Annealing
Nationell ämneskategori
Datavetenskap (datalogi)
Forskningsämne
Datalogi
Identifikatorer
urn:nbn:se:kth:diva-310910 (URN)10.5220/0010823800003120 (DOI)000818770500009 ()2-s2.0-85176317924 (Scopus ID)
Konferens
8th International Conference on Information Systems Security and Privacy (ICISSP), Virtual/Online, 9-11 February, 2022
Projekt
SOCCRATES
Forskningsfinansiär
Security Link, 833481
Anmärkning

Part of proceedings: ISBN 978-989-758-553-1

QC 20220419

QC 20220708

Tillgänglig från: 2022-04-11 Skapad: 2022-04-11 Senast uppdaterad: 2023-11-23Bibliografiskt granskad
Widel, W., Mukherjee, P. & Ekstedt, M. (2022). Security Countermeasures Selection Using the Meta Attack Language and Probabilistic Attack Graphs. IEEE Access, 10, 89645-89662
Öppna denna publikation i ny flik eller fönster >>Security Countermeasures Selection Using the Meta Attack Language and Probabilistic Attack Graphs
2022 (Engelska)Ingår i: IEEE Access, E-ISSN 2169-3536, Vol. 10, s. 89645-89662Artikel i tidskrift (Refereegranskat) Published
Abstract [en]

Connecting critical infrastructure assets to the network is absolutely essential for modern industries. In contrast to the apparent advantages, network connectivity exposes other infrastructure vulnerabilities that can be exploited by attackers. To protect the infrastructure, precise countermeasure identification is necessary. In this regard, the objective for the security officers is to identify the optimal set of countermeasures under a variety of budgetary restrictions. Our approach is based on the Meta Attack Language framework, which allows for convenient modelling of said infrastructures, as well as for automatic generation of attack graphs describing attacks against them. We formalize the problem of the selection of countermeasures in this context. The formalization makes it possible to deal with an arbitrary number of budgets, expressing available resources of both monetary and time-like nature, and to model numerous dependencies between countermeasures, including order dependencies, mutual exclusivity, and interdependent implementation costs. We propose a flexible and scalable algorithm for the problem. The whole methodology is validated in practice on realistic models.

Ort, förlag, år, upplaga, sidor
Institute of Electrical and Electronics Engineers (IEEE), 2022
Nationell ämneskategori
Datavetenskap (datalogi)
Identifikatorer
urn:nbn:se:kth:diva-316948 (URN)10.1109/access.2022.3200601 (DOI)000848230900001 ()2-s2.0-85137583573 (Scopus ID)
Anmärkning

QC 20220920

Tillgänglig från: 2022-09-01 Skapad: 2022-09-01 Senast uppdaterad: 2022-09-20Bibliografiskt granskad
Organisationer
Identifikatorer
ORCID-id: ORCID iD iconorcid.org/0000-0003-2549-6578

Sök vidare i DiVA

Visa alla publikationer