A framework to facilitate cyber defense situational awareness modeled in an emulated virtual machine testbed

被引:1
|
作者
Raulerson, Evan L. [1 ]
Hopkinson, Kenneth M. [2 ]
Laviers, Kennard R. [2 ]
机构
[1] US Air Force, Inst Technol, Dept Elect & Comp Engn, Wright Patterson AFB, OH 45433 USA
[2] US Air Force, Inst Technol, Dept Elect & Comp Engn, Comp Sci, Wright Patterson AFB, OH 45433 USA
关键词
Cyberspace; intrusion detection; local area networks; modeling; sensor fusion;
D O I
10.1177/1548512914552530
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Modern computer networks and the cyber attacks launched against them grow more complex each year. Analyzing network information can be complex and time consuming. Network defenders are routinely unable to orient themselves quickly enough to determine the expected system impact, much less defend the networks' resources. The network operator's time would be better spent finding and executing event responses to minimize damage. Current automated response systems are mostly limited to scripted responses based on data from a single source. Better automation is required. This paper presents a framework that aggregates data from heterogeneous network sensors, including intrusion detection systems and network vulnerability assessment tools. An impact rating system is proposed and tested that estimates the feasibility of an attack and its potential impact. The impact assessments allow decision makers to prioritize attacks in real time and attempt to mitigate the attacks in order of their estimated network impact to the network. Experimental results indicated that when administrators are only concerned with high-level attacks, impact assessments could eliminate a mean 51.21% of irrelevant data. When only concerned with high-and medium-level attacks, a mean of 34.03% of the data was irrelevant. This represents a significant reduction in the information administrators must process.
引用
收藏
页码:229 / 239
页数:11
相关论文
共 23 条
  • [1] The Role of Situational Awareness in Cyber Security and Cyber Defense Strategy
    Onwubiko, Cyril
    [J]. 2015 International Conference on Cyber Situational Awareness, Data Analytics and Assessment (CyberSA), 2015,
  • [2] Cyber Situational Awareness and Mission-Centric Resilient Cyber Defense
    Lei, Jingmin
    [J]. PROCEEDINGS OF 2015 4TH INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2015), 2015, : 1218 - 1225
  • [3] Framework for risk assessment in cyber situational awareness
    Xi Rongrong
    Yun Xiaochun
    Hao Zhiyu
    [J]. IET INFORMATION SECURITY, 2019, 13 (02) : 149 - 156
  • [4] Study on Cyber Common Operational Picture Framework for Cyber Situational Awareness
    Kim, Kookjin
    Youn, Jaepil
    Yoon, Sukjoon
    Kang, Jiwon
    Kim, Kyungshin
    Shin, Dongkyoo
    [J]. APPLIED SCIENCES-BASEL, 2023, 13 (04):
  • [5] Situational Awareness Framework for Cyber Crime Prevention Model in Cyber Physical System
    Joo, Minhee
    Seo, Junwoo
    Oh, Junhyoung
    Park, Mookyu
    Lee, Kyungho
    [J]. 2018 TENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2018), 2018, : 837 - 842
  • [6] A Cyber Security Situational Awareness Framework to Track and Project Multistage Cyber Attacks
    Bhatt, Parth
    Yano, Edgar Toshiro
    Amorim, Joni
    Gustavsson, Per
    [J]. PROCEEDINGS OF THE 9TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS-2014), 2014, : 356 - 360
  • [7] Cauldron Mission-Centric Cyber Situational Awareness with Defense in Depth
    Jajodia, Sushil
    Noel, Steven
    Kalapa, Pramod
    Albanese, Massimiliano
    Williams, John
    [J]. 2011 - MILCOM 2011 MILITARY COMMUNICATIONS CONFERENCE, 2011, : 1339 - 1344
  • [8] Gamification as a neuroergonomic approach to improving interpersonal situational awareness in cyber defense
    Ask, Torvald F.
    Knox, Benjamin J.
    Lugo, Ricardo G.
    Hoffmann, Lukas
    Suetterlin, Stefan
    [J]. FRONTIERS IN EDUCATION, 2023, 8
  • [9] A Conceptual Nationwide Cyber Situational Awareness Framework for Critical Infrastructures
    Bahsi, Hayretdin
    Maennel, Olaf Manuel
    [J]. SECURE IT SYSTEMS, NORDSEC 2015, 2015, 9417 : 3 - 10
  • [10] Towards a Theoretical Framework for an Active Cyber Situational Awareness Model
    Al-Shamisi, Ahmed
    Louvieris, Panos
    Al-Mualla, Mohammed
    Mihajlov, Martin
    [J]. PROCEEDINGS OF THE 23RD INTERNATIONAL CONFERENCE ON SYSTEMS, SIGNALS AND IMAGE PROCESSING, (IWSSIP 2016), 2016, : 263 - 268