KIT | KIT-Bibliothek | Impressum | Datenschutz

Weighted attack graphs and behavioral cyber game theory for cyber risk quantification

Kaiser, Florian K. 1; Wiens, Marcus; Schultmann, Frank ORCID iD icon 1
1 Institut für Industriebetriebslehre und Industrielle Produktion (IIP), Karlsruher Institut für Technologie (KIT)

Abstract:

Operating and engineering secure systems is challenging yet a necessary prerequisite for modern life as we know it, flourishing economic systems and society as a whole. This is as digitalization penetrated broad aspects of every facet of life realizing many opportunities. However, digital transformation also leads to increasing vulnerability to cyber threats. Cyber risk quantification thereby has a crucial role as anything that “is not measured cannot be improved. [And] what is not improved will always degrade” (Thomas Kelvin). However, quantifying cyber risks respectively as an inverse quantifying cyber security is still in its infancy and a largely unsolved problem.

We propose a novel methodology for cyber risk quantification based on weighted attack graphs. By doing so, we introduce a multi-layered attack ontology which is the basis of the attack graph. The attack graph is developed relying on cyber threat intelligence. We weight each attack path using computational models of motivation. The attack graph is the basis of a defender-attacker game. We analyze and solve the game for deriving quantitative measures describing the risk of getting attacked.


Originalveröffentlichung
DOI: 10.1201/9781003269144-2
Zugehörige Institution(en) am KIT Institut für Industriebetriebslehre und Industrielle Produktion (IIP)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Buchaufsatz
Publikationsdatum 21.12.2022
Sprache Englisch
Identifikator ISBN: 978-1-03-221600-3
KITopen-ID: 1000153634
HGF-Programm 46.23.04 (POF IV, LK 01) Engineering Security for Production Systems
Weitere HGF-Programme 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Advances in Cyber Security and Intelligent Analytics. Ed.: A. Verma
Auflage 1
Verlag CRC Press-Taylor & Francis Group
Seiten 27-42
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page