Defensive Cyber Battle Damage Assessment Through Attack Methodology Modeling

Abstract

Due to the growing sophisticated capabilities of advanced persistent cyber threats, it is necessary to understand and accurately assess cyber attack damage to digital assets. This thesis proposes a Defensive Cyber Battle Damage Assessment (DCBDA) process which utilizes the comprehensive understanding of all possible cyber attack methodologies captured in a Cyber Attack Methodology Exhaustive List (CAMEL). This research proposes CAMEL to provide detailed knowledge of cyber attack actions, methods, capabilities, forensic evidence and evidence collection methods. This product is modeled as an attack tree called the Cyber Attack Methodology Attack Tree (CAMAT). The proposed DCBDA process uses CAMAT to analyze potential attack scenarios used by an attacker. These scenarios are utilized to identify the associated digital forensic methods in CAMEL to correctly collect and analyze the damage from a cyber attack. The results from the experimentation of the proposed DCBDA process show the process can be successfully applied to cyber attack scenarios to correctly assess the extent, method and damage caused by a cyber attack.

Open PDF

Document Details

Document Type
Technical Report
Publication Date
Mar 25, 2011
Accession Number
ADA539975

Entities

People

  • Ryan Ostler

Organizations

  • Air Force Institute of Technology

Tags

Communities of Interest

  • Cyber

DTIC Thesaurus Topics

  • Air Force
  • Application Software
  • Battle Damage Assessment
  • Computer Network Security
  • Computer Networks
  • Computer Program Documentation
  • Computer Program Reliability
  • Computer Programming
  • Computer Programs
  • Computer Science
  • Computers
  • Cyberattacks
  • Cybersecurity
  • Information Systems
  • Malware
  • Operating Systems
  • Web Browsers

Fields of Study

  • Computer science

Readers

  • Computational Modeling and Simulation
  • Military Science and Technology Research and Modernization.
  • Missile Defense Systems.

Technology Areas

  • Cyber