1. Defensive Cyber Operations Support Model : optimisation of a multilayered tri-level game model for mission-centric risk prioritisation
- Author
-
Mallon, S. and Mallon, S.
- Abstract
NLDA Masterthesis ; MTPS, In this research, a defensive cyber operations risk model is designed, implemented, verified, and validated. This risk model can enable the prioritisation of vulnerabilities by military decision-makers in Defensive Cyber Operations (DCO), allowing them to take mitigating measures, specifically patching and updating of software, with minimum reliance on Subject Matter Expert (SME) estimations. Models of more traditional risk analysis frameworks often rely heavily on SME estimations formed by very limited Cyber Threat Intelligence (CTI), with often questionable accuracy and poor substantiation. Also the output of such frameworks is often ambiguous and requires domain expertise to interpret. These issues make models of traditional risk analysis frameworks less suitable for cyber security support in a military context. The proposed model is a multilayered network graph representation combined with game and graph-based analysis techniques implemented as a constraint program. One of the main ideas behind this approach is that it can determine the possible impact of cyber threats on military missions by mapping the mission dependencies to IT services and assets. The multiple layers consist of an attack graph representation of the weapon system and a dependency graph representation of the subsystems, capabilities and processes. The model simulates attacks on the attack graphs, and through the affected subsystems, the attacks propagate to the system layer. In this layer, the effect on the mission is determined. A zero-sum game-theoretic method has been designed for analysis, consisting of three players; an operator, an attacker and a defender. This technique is considered less reliant on SME likelihood than other techniques, such as Bayesian methods. Together with attack graph analysis, which incorporates the well known and broadly accepted Common Vulnerability Scoring System (CVSS) metric as a basis parameter, there is only a minimal requirement of SME estimations. Besides
- Published
- 2022