Improved Cyber Defense Modeling Framework for Modeling and Simulating the Lifecycle of Cyber Defense Activities

被引:1
|
作者
Kim, Donghwa [1 ,2 ]
Ahn, Myung Kil [1 ]
Lee, Seongkee [1 ]
Lee, Donghwan [1 ]
Park, Moosung [1 ]
Shin, Dongkyoo [2 ,3 ]
机构
[1] Agcy Def Dev, Cyber Technol Ctr, Seoul 05771, South Korea
[2] Sejong Univ, Dept Comp Engn, Seoul 05006, South Korea
[3] Sejong Univ, Dept Convergence Engn Intelligent Drone, Seoul 05006, South Korea
关键词
Cybersecurity modeling and simulation; cyber defense model; cyber defense process model; ATTACK;
D O I
10.1109/ACCESS.2023.3324901
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
It is difficult to assess the business impact of a cyberattack and implement appropriate strategies or policies to enhance cyber resilience and counter future attacks. Penetration testing, which is currently gaining popularity, has been employed to assess cyber defense levels in actual operating environments. However, it is expensive and time-consuming and only reveals the current state of a problem without providing insights into potentially better alternative strategies. To overcome these limitations, cybersecurity modeling and simulation (M&S) research, which includes the crucial component of cyber-defense modeling, is being actively conducted. Most cyber defense modeling approaches only model defenses as a response to cyberattacks, neglecting to consider the complexities in the actual cyber defense activities of organizations. Consequently, the intended aim to evaluate and enhance cyber defense capabilities through analysis cannot be met. In this study, we present a cyber defense process model that models the entire lifecycle of cyber defense activities as the following five phases: prevention, monitoring and detection, initial response, attack analysis, and recovery response. This model not only accounts for defense steps that had been neglected in previous studies but also offers improvements to previously introduced defense steps. Additionally, we present a framework for applying initial and recovery response models by progressively integrating a unit response behavior model to counter cyberattacks. The applicability of the proposed model was verified by using a constructed prototype. The results of this study can be applied to developing an M&S-based experimental environment for assessing the sustainability of missions/businesses that have faced cyberattacks.
引用
收藏
页码:114187 / 114200
页数:14
相关论文
共 50 条
  • [1] Modeling and simulation to support cyber defense
    Damodaran, Suresh K.
    Wagner, Neal
    JOURNAL OF DEFENSE MODELING AND SIMULATION-APPLICATIONS METHODOLOGY TECHNOLOGY-JDMS, 2020, 17 (01): : 3 - 4
  • [2] A cyber defense framework
    Kang, MH
    Mayfield, T
    8TH WORLD MULTI-CONFERENCE ON SYSTEMICS, CYBERNETICS AND INFORMATICS, VOL II, PROCEEDINGS: COMPUTING TECHNIQUES, 2004, : 526 - 531
  • [3] Cyber defense in breadth: Modeling and analysis of integrated defense systems
    Cho, Jin-Hee
    Ben-Asher, Noam
    JOURNAL OF DEFENSE MODELING AND SIMULATION-APPLICATIONS METHODOLOGY TECHNOLOGY-JDMS, 2018, 15 (02): : 147 - 159
  • [4] Multi-paradigm deception modeling for cyber defense
    De Faveri, Cristiano
    Moreira, Ana
    Amaral, Vasco
    JOURNAL OF SYSTEMS AND SOFTWARE, 2018, 141 : 32 - 51
  • [5] Modeling and Analysis of the Decentralized Interactive Cyber Defense Approach
    Ming Liu
    Ruiguang Li
    Weiling Chang
    Jieming Gu
    Shouying Bai
    Jia Cui
    Lu Ma
    China Communications, 2022, 19 (10) : 116 - 128
  • [6] Modeling and Analysis of the Decentralized Interactive Cyber Defense Approach
    Liu, Ming
    Li, Ruiguang
    Chang, Weiling
    Gu, Jieming
    Bai, Shouying
    Cui, Jia
    Ma, Lu
    CHINA COMMUNICATIONS, 2022, 19 (10) : 116 - 128
  • [7] A Survey on Cyber-Attacks for Cyber-Physical Systems: Modeling, Defense, and Design
    Lian, Zhi
    Shi, Peng
    Chen, Mou
    IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (02): : 1471 - 1483
  • [8] Framework and principles for active cyber defense
    Denning, Dorothy E.
    COMPUTERS & SECURITY, 2014, 40 : 108 - 113
  • [9] MODELING AND SIMULATION OF COOPERATION AND LEARNING IN CYBER SECURITY DEFENSE TEAMS
    Legato, Pasquale
    Mazza, Rina Mary
    PROCEEDINGS - 31ST EUROPEAN CONFERENCE ON MODELLING AND SIMULATION ECMS 2017, 2017, : 502 - 509
  • [10] Modeling of Intrusion and Defense for Assessment of Cyber Security at Power Substations
    Chen, Ying
    Hong, Junho
    Liu, Chen-Ching
    IEEE TRANSACTIONS ON SMART GRID, 2018, 9 (04) : 2541 - 2552