Timing and Resilience in Cyber Conflict: A Theoretical Framework

被引:0
|
作者
Connett, Brian [1 ]
机构
[1] US Naval Postgrad Sch, Monterey, CA 93943 USA
关键词
critical infrastructure; cyber physical systems; modeling; cyber threat;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The critical infrastructure is a cyber physical system (CPS) of the global economy, transportation, health and quality of life systems that is poised to fail under precisely, or even loosely, coordinated attacks. Since inception, systems assets within critical infrastructures were seemingly safe from the exploitation or attack by nefarious cyberspace actors. Now, critical infrastructure is a target because the resources to exploit the cyber physical systems exist. The fragility of critical infrastructure networks is a product of poor planning and an aging technology-dependent distributed system. That fragility is amplified with a decreasing learning curve associated with the growing population of cyber-actors. To compound this aggregated problem, the immeasurable scale of connected and complex networked cyber physical systems limits the resources with which the system, itself, can adequately monitor the entirety of its ongoing processes. A lack of ability to effectively monitor complex systems, and correctly identify when an anomaly is present motivates the research this work uses to build its position. System owners are obligated to maintain a high level of protection measures against exploitation resources, characterized in terms of patience, stealth, replication-ability and extraordinary robustness. The difficulty lies in knowing when, how and where to fortify a critical infrastructure against an impending attack. Models currently exist that theorize the value of knowing the attacker's capabilities in the cyber realm, taking into consideration of the strength of the target, but they are not designed to respond to the inherent fast timing of an attack, an impetus that can be derived based on open-source reporting, common knowledge of exploits and the physical architecture of the infrastructure. This dissertation seeks to build a framework and architecture with a useful model that will inform systems owners how to align infrastructure architecture in a manner that is responsive to the capability, willingness and timing of the attacker. This research group will use existing theoretical models for estimating the functional parameters, and through analysis, develop a decision tool for would-be target owners. Systems owner requires a decision system that can be scalable across temporal and physical boundaries and is capable of detecting an anomaly, and then informing the system owner of an attack's potential dispersion. The complement to this capability need is a system which demonstrates a triad of availability, namely in the terms of resilience, adaptability and predictability. An architecture is introduced to ensure that the observed anomaly, if allowed to persist, will only do so at the thresholds within the triad set by the system owner. While not static through time iterations, the thresholds provide a situationally aware decision to allow an overall availability, consistent with the need and utility of a critical infrastructure service.
引用
收藏
页码:415 / 418
页数:4
相关论文
共 50 条
  • [1] Timing of cyber conflict
    Axelrod, Robert
    Iliev, Rumen
    PROCEEDINGS OF THE NATIONAL ACADEMY OF SCIENCES OF THE UNITED STATES OF AMERICA, 2014, 111 (04) : 1298 - 1303
  • [2] Cyber security and the disaster resilience framework
    Panda, Abhilash
    Bower, Andrew
    INTERNATIONAL JOURNAL OF DISASTER RESILIENCE IN THE BUILT ENVIRONMENT, 2020, 11 (04) : 507 - 518
  • [3] KNOWLEDGE BASED FRAMEWORK FOR CYBER WEAPONS AND CONFLICT
    Lorents, Peeter
    Ottis, Rain
    CONFERENCE ON CYBER CONFLICT, PROCEEDINGS 2010, 2010, : 129 - 142
  • [4] Organizational cyber resilience: toward an integrative conceptual framework
    Neri, Martina
    Niccolini, Federico
    Virili, Francesco
    MANAGEMENT REVIEW QUARTERLY, 2025,
  • [5] Digitalization Capabilities for Sustainable Cyber Resilience: A Conceptual Framework
    Annarelli, Alessandro
    Palombi, Giulia
    SUSTAINABILITY, 2021, 13 (23)
  • [6] Need for a Cyber Resilience Framework for Critical Space Infrastructure
    Shahzad, Syed
    Qiao, Li
    Joiner, Keith
    PROCEEDINGS OF THE 17TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2022), 2022, : 404 - 412
  • [7] Systems engineering framework for cyber physical security and resilience
    DiMase D.
    Collier Z.A.
    Heffner K.
    Linkov I.
    Environment Systems and Decisions, 2015, 35 (2) : 291 - 300
  • [8] A Modelling Framework for Cyber-Physical System Resilience
    Bujorianu, Manuela L.
    Piterman, Nir
    CYBER PHYSICAL SYSTEMS: DESIGN, MODELING, AND EVALUATION, CYPHY 2015, 2015, 9361 : 67 - 82
  • [9] Towards a Cyber Resilience Quantification Framework (CRQF) for IT infrastructure
    Alhidaifi, Saleh Mohamed
    Asghar, Muhammad Rizwan
    Ansari, Imran Shafique
    COMPUTER NETWORKS, 2024, 247
  • [10] Towards a Theoretical Framework for Trustworthy Cyber Sensing
    Xu, Shouhuai
    CYBER SECURITY, SITUATION MANAGEMENT, AND IMPACT ASSESSMENT II; AND VISUAL ANALYTICS FOR HOMELAND DEFENSE AND SECURITY II, 2010, 7709