Open this publication in new window or tab >>2022 (English)In: Proceedings of the 8th international conference on information systems security and privacy (ICISSP) / [ed] Paolo Mori, Gabriele Lenzini, Steven Furnell, Scitepress , 2022, Vol. 1, p. 108-120Conference paper, Published paper (Refereed)
Abstract [en]
Foreseeing, mitigating and preventing cyber-attacks is more important than ever before. Advances in the field of probabilistic threat modelling can help organisations understand their own resilience profile against cyber-attacks. Previous research has proposed MAL, a meta language for capturing the attack logic of a considered domain and running attack simulations in a model that depicts the defended IT-infrastructure. While this modality is already somewhat established for proposing general threat mitigation actions, less is known about how to model containment strategies in the event that penetration already has occurred. The problem is a fundamental gap between predominant threat models in cyber-security research and containment in the incident response lifecycle. This paper presents a solution to the problem by summarizing a methodology for reasoning about containment strategies in MAL-based threat models.
Place, publisher, year, edition, pages
Scitepress, 2022
Series
Proceedings of the 8th International Conference on Information Systems Security and Privacy 2022, ISSN 2184-4356
Keywords
Threat Analysis, MAL, Containment strategies, Simulated Annealing
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
urn:nbn:se:kth:diva-310910 (URN)10.5220/0010823800003120 (DOI)000818770500009 ()2-s2.0-85176317924 (Scopus ID)
Conference
8th International Conference on Information Systems Security and Privacy (ICISSP), Virtual/Online, 9-11 February, 2022
Projects
SOCCRATES
Funder
Security Link, 833481
Note
Part of proceedings: ISBN 978-989-758-553-1
QC 20220419
QC 20220708
2022-04-112022-04-112023-11-23Bibliographically approved