Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Containment Strategy Formalism in a Probabilistic Threat Modelling Framework
KTH, Skolan för elektroteknik och datavetenskap (EECS).ORCID-id: 0000-0002-1639-2673
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Nätverk och systemteknik.ORCID-id: 0000-0003-3922-9606
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Nätverk och systemteknik.ORCID-id: 0000-0003-2549-6578
KTH, Skolan för elektroteknik och datavetenskap (EECS), Datavetenskap, Nätverk och systemteknik.ORCID-id: 0000-0002-4641-9240
2022 (engelsk)Inngår i: Proceedings of the 8th international conference on information systems security and privacy (ICISSP) / [ed] Paolo Mori, Gabriele Lenzini, Steven Furnell, Scitepress , 2022, Vol. 1, s. 108-120Konferansepaper, Publicerat paper (Fagfellevurdert)
Abstract [en]

Foreseeing, mitigating and preventing cyber-attacks is more important than ever before. Advances in the field of probabilistic threat modelling can help organisations understand their own resilience profile against cyber-attacks. Previous research has proposed MAL, a meta language for capturing the attack logic of a considered domain and running attack simulations in a model that depicts the defended IT-infrastructure. While this modality is already somewhat established for proposing general threat mitigation actions, less is known about how to model containment strategies in the event that penetration already has occurred. The problem is a fundamental gap between predominant threat models in cyber-security research and containment in the incident response lifecycle. This paper presents a solution to the problem by summarizing a methodology for reasoning about containment strategies in MAL-based threat models.

sted, utgiver, år, opplag, sider
Scitepress , 2022. Vol. 1, s. 108-120
Serie
Proceedings of the 8th International Conference on Information Systems Security and Privacy 2022, ISSN 2184-4356
Emneord [en]
Threat Analysis, MAL, Containment strategies, Simulated Annealing
HSV kategori
Forskningsprogram
Datalogi
Identifikatorer
URN: urn:nbn:se:kth:diva-310910DOI: 10.5220/0010823800003120ISI: 000818770500009Scopus ID: 2-s2.0-85176317924OAI: oai:DiVA.org:kth-310910DiVA, id: diva2:1651148
Konferanse
8th International Conference on Information Systems Security and Privacy (ICISSP), Virtual/Online, 9-11 February, 2022
Prosjekter
SOCCRATES
Forskningsfinansiär
Security Link, 833481
Merknad

Part of proceedings: ISBN 978-989-758-553-1

QC 20220419

QC 20220708

Tilgjengelig fra: 2022-04-11 Laget: 2022-04-11 Sist oppdatert: 2023-11-23bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Andre lenker

Forlagets fulltekstScopusConference

Person

Fahlander, PerEkstedt, MathiasMukherjee, PreetamDwivedi, Ashish Kumar

Søk i DiVA

Av forfatter/redaktør
Fahlander, PerEkstedt, MathiasMukherjee, PreetamDwivedi, Ashish Kumar
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

doi
urn-nbn

Altmetric

doi
urn-nbn
Totalt: 174 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf