2022
DOI: 10.1002/eng2.12538
|View full text |Cite
|
Sign up to set email alerts
|

Mission‐centric decision support in cybersecurity via Bayesian Privilege Attack Graph

Abstract: We present an approach to decision support in cybersecurity with respect to cyber threats and stakeholders' requirements. We approach situations in which cybersecurity experts need to take actions to mitigate the risks, such as temporarily putting an IT system out of operation, but need to consult them with other stakeholders. We propose a decision support system that uses a mission decomposition model representing the organization's functional and security requirements on its IT infrastructure. Based on the c… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
11
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
4
1
1

Relationship

1
5

Authors

Journals

citations
Cited by 10 publications
(13 citation statements)
references
References 67 publications
0
11
0
Order By: Relevance
“…We the following four MIA approaches: (i) iMIA-SBN-E-Prior: The proposed iMIA uses SBN with an expert's opinions for prior knowledge, implying that prior knowledge is aligned with ground truth states (i.e., uncertainty is interpreted correctly); (ii) iMIA-SBN-No-Prior: The iMIA uses SBN without prior knowledge; (iii) iMIA-BN-Prior: The iMIA uses BN with prior knowledge (i.e., 𝐵𝑒𝑡𝑎(1, 1)). Since most MIA approaches [12,[15][16][17] have used BN with prior knowledge, this scheme can represent the conventional MIA; and (iv) iMIA-BN-No-Prior: The iMIA uses BN without prior knowledge (i.e., 𝐵𝑒𝑡𝑎(0, 0)). (2) Mission performance analysis of the iMIA under various attack-defense interactions.…”
Section: Methodsmentioning
confidence: 99%
See 4 more Smart Citations
“…We the following four MIA approaches: (i) iMIA-SBN-E-Prior: The proposed iMIA uses SBN with an expert's opinions for prior knowledge, implying that prior knowledge is aligned with ground truth states (i.e., uncertainty is interpreted correctly); (ii) iMIA-SBN-No-Prior: The iMIA uses SBN without prior knowledge; (iii) iMIA-BN-Prior: The iMIA uses BN with prior knowledge (i.e., 𝐵𝑒𝑡𝑎(1, 1)). Since most MIA approaches [12,[15][16][17] have used BN with prior knowledge, this scheme can represent the conventional MIA; and (iv) iMIA-BN-No-Prior: The iMIA uses BN without prior knowledge (i.e., 𝐵𝑒𝑡𝑎(0, 0)). (2) Mission performance analysis of the iMIA under various attack-defense interactions.…”
Section: Methodsmentioning
confidence: 99%
“…• Compared to the common use of Bayesian Network in inferring mission impact by existing MIA approaches [12,[15][16][17] 1 , our work first uses Subjective Bayesian Network (SBN)-based reasoning model [18] to infer the mission outcome in an AI-based mission system. Our previous study [19] introduced a software-centric MIA framework using SBN combining BN and Subjective Logic (SL) [18] to assess an Unmanned Aerial Vehicle (UAV)-based mission system.…”
Section: B Key Contributionsmentioning
confidence: 99%
See 3 more Smart Citations