kth.sePublications KTH
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
An Attack Simulation Language for the IT Domain
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Network and Systems Engineering.ORCID iD: 0000-0001-8287-3160
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Network and Systems Engineering.ORCID iD: 0000-0003-0478-9347
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Network and Systems Engineering.ORCID iD: 0000-0002-3293-1681
KTH, School of Electrical Engineering and Computer Science (EECS), Computer Science, Network and Systems Engineering.ORCID iD: 0000-0003-3922-9606
Show others and affiliations
2020 (English)In: Graphical Models for Security: 7th International Workshop, GraMSec 2020, Boston, MA, USA, June 22, 2020, Revised Selected Papers, Springer Nature , 2020, Vol. 12419, p. 67-86Conference paper, Published paper (Refereed)
Abstract [en]

Cyber-attacks on IT infrastructures can have disastrous consequences for individuals, regions, as well as whole nations. In order to respond to these threats, the cyber security assessment of IT infrastructures can foster a higher degree of security and resilience against cyber-attacks. Therefore, the use of attack simulations based on system architecture models is proposed. To reduce the effort of creating new attack graphs for each system under assessment, domain-specific languages (DSLs) can be employed. DSLs codify the common attack logics of the considered domain. Previously, MAL (the Meta Attack Language) was proposed, which serves as a framework to develop DSLs and generate attack graphs for modeled infrastructures. In this article, we propose coreLang as a MAL-based DSL for modeling IT infrastructures and analyzing weaknesses related to known attacks. To model domain-specific attributes, we studied existing cyber-attacks to develop a comprehensive language, which was iteratively verified through a series of brainstorming sessions with domain modelers. Finally, this first version of the language was validated against known cyber-attack scenarios.

Place, publisher, year, edition, pages
Springer Nature , 2020. Vol. 12419, p. 67-86
Series
Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), ISSN 0302-9743 ; 12419
Keywords [en]
Attack graphs, Attack simulation, Domain specific language, IT Infrastructure, Meta Attack Language, Threat modeling, Computer simulation languages, Crime, Digital subscriber lines, Graphic methods, Network security, Problem oriented languages, Attack graph, Brainstorming sessions, Cyber security, Cyber-attacks, Domain specific languages, IT infrastructures, Model domains, System architectures, Computer crime
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:kth:diva-290393DOI: 10.1007/978-3-030-62230-5_4Scopus ID: 2-s2.0-85097391406OAI: oai:DiVA.org:kth-290393DiVA, id: diva2:1529801
Conference
7th International Workshop on Graphical Models for Security, GramSec 2020; Boston; United States; 22 June 2020 through 22 June 2020
Note

QC 20210219

Available from: 2021-02-19 Created: 2021-02-19 Last updated: 2022-12-20Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full textScopus

Authority records

Katsikeas, SotiriosHacks, SimonJohnson, PontusEkstedt, MathiasLagerström, Robert

Search in DiVA

By author/editor
Katsikeas, SotiriosHacks, SimonJohnson, PontusEkstedt, MathiasLagerström, Robert
By organisation
Network and Systems Engineering
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric score

doi
urn-nbn
Total: 1951 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf