Mapping the Cyber Terrain: Enabling Cyber Defensibility Claims and Hypotheses to Be Stated and Evaluated with Greater Rigor and Utility

Abstract

Evidence and analysis are needed to determine the effectiveness of cyber security, defensibility, and resiliency solutions. Claims or hypotheses about effectiveness generally are based on assumptions about the threat, and about the technical and operational settings in which solutions will be used. Evidence can be obtained in a variety of environments, ranging from conceptual models to systems supporting mission operations. This paper presents a framework for characterizing assumptions and evaluation environments - an approach to mapping the cyber terrain. The approach presented here can facilitate determination of whether a given hypothesis is meaningful to a specific real-world situation or can be evaluated in a given environment, whether different solutions can be evaluated in a common environment, and whether or how the results obtained in a given environment can be applied to real-world situations. Examples are provided of questions to ask, and sources of information to use, to characterize an environment, particularly with respect to the threat.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Nov 01, 2013
Accession Number
AD1107342

Entities

People

  • Deborah Bodeau
  • Richard D. Graubart
  • William Heinbockel

Organizations

  • MITRE Corporation

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Computational Science
  • Computer Network Security
  • Computers
  • Computing System Architectures
  • Contingency Operations (Military)
  • Control Systems
  • Crime
  • Cyber Defense Techniques
  • Cyber Protection
  • Cyber Threats
  • Cyberattacks
  • Cybersecurity
  • Cyberspace Operations
  • Department Of Homeland Security
  • Emergency Response
  • Failure Mode And Effect Analysis
  • Information Exchange
  • Information Processing
  • Information Science
  • Information Security
  • Information Systems
  • Intrusion Detection
  • Military Science
  • Reliability
  • Situational Awareness
  • Systems Engineering
  • Test And Evaluation

Readers

  • Computer Vision.
  • Irregular Warfare and Special Operations Cyberspace Operations against Adversarial Threats.
  • Theoretical Analysis.

Technology Areas

  • Cyber