课题基金 / 基金详情

CRII: SaTC: Graph-based Probabilistic Cyber Risk Modeling

CRII: SaTC: Graph-based Probabilistic Cyber Risk Modeling
CRII:SaTC:基于图的概率网络风险建模
批准号:
1948261
负责人:
Unal Tatar
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-04-01 至 2023-03-31

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
网络安全风险分析是管理网络事件后果的主要工具之一。现有的网络安全风险分析方法存在一些局限性。首先,网络风险往往被视为一个信息技术问题,而不是企业风险管理的重要组成部分。网络风险分析方法的另一个不足是所使用的指标不足以支持投资决策。定性指标和操作术语通常被用作网络风险指标,而不是指导投资决策的量化财务指标。除此之外,缺乏对特定控制措施的投资如何改变风险水平的量化是当前网络风险分析方法的另一个局限性。本项目旨在针对目前网络风险分析方法的上述不足,建立一个概率定量的网络安全风险分析模型,将资产级风险与组织级风险和供应链级风险联系起来。这项研究的结果能够实现有效和准确的供应链网络风险评估,从而通过更有效和高效地缓解网络风险和明智的网络安全投资来提高经济竞争力。该项目为不同层次和代表性不足群体的学生提供培训机会。该项目开发的教育材料将通过国家安全局支持的CLARK网络安全学习对象库在全国范围内共享。本研究的主要研究问题是如何建立一种概率定量的网络安全风险分析模型,将资产级风险与组织级风险和供应链级风险联系起来。该项目采用概率攻击图,它基于计算机软件和网络拓扑结构中的已知漏洞。利用贝叶斯信念网络增强了攻击图的动态风险评估能力。我们还开发了一个图理论的功能依赖模型来模拟网络攻击对供应链中企业任务失败的连锁反应。在智能电网试验台上进行了仿真和灵敏度分析,验证了所建立的风险分析模型。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Cybersecurity risk analysis is one of the primary tools for managing the consequences of cyber incidents. There are several limitations of the current cybersecurity risk analysis methods. First, cyber risk is often treated as an information technology problem rather than a vital part of enterprise risk management. Another deficiency of the cyber risk analysis methods is the insufficiency of the utilized metrics to support investment decisions. Qualitative metrics and operational terms are often used as cyber risk indicators rather than quantified financial measures that guide investment decisions. Besides these, the lack of quantification of how investments in specific controls change risk level is another limitation of the current cyber risk analysis methods. This project aims to develop a probabilistic quantitative cybersecurity risk analysis model to relate asset-level risk to organizational-level risk and supply chain level risk to respond to the aforementioned deficiencies of the current cyber risk analysis methods. The results from this research enables effective and accurate supply-chain cyber risk assessment, which, in turn, increases economic competitiveness by enabling more effective and efficient mitigation of cyber risks and well-informed cybersecurity investments. The project provides training opportunities for students at different levels and from under-represented groups. Education materials developed in the project will be shared nationally through the National Security Agency supported CLARK repository of cybersecurity learning objects.The main research problem of this study is what kind of a probabilistic quantitative cybersecurity risk analysis model can be developed to relate asset-level risk to organizational-level risk and supply chain level risk. This project employs probabilistic attack graphs, which are based on known vulnerabilities in computer software and network topologies. The dynamic risk assessment capabilities are augmented in the attack graph using Bayesian Belief Networks. A graph-theoretical functional dependency model is also developed to model the ripple effects of cyber-attacks on enterprise missions to failures in supply-chains. Simulations and sensitivity analysis are conducted on a smart grid testbed to validate the developed risk analysis model.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
Scoring Cyber Vulnerabilities based on Their Impact on Organizational Goals *
根据网络漏洞对组织目标的影响对网络漏洞进行评分 *
DOI: 10.1109/sieds52267.2021.9483741
发表时间: 2021
期刊: 2021 Systems and Information Engineering Design Symposium (SIEDS
影响因子: --
作者: [Keskin, Omer, Gannon, Nick, Lopez, Brian, Tatar, Unal]
通讯作者: Tatar, Unal
Managing Physical and Economic Risk for Systems with Multidirectional Network Interdependencies
管理具有多向网络相互依赖性的系统的物理和经济风险
DOI: 10.1111/risa.13824
发表时间: 2022
期刊: Risk Analysis
影响因子: 3.8
作者: [Tatar, Unal, Santos, Joost R., Thekdi, Shital A.]
通讯作者: Thekdi, Shital A.
DOI: 10.3390/electronics10101168
发表时间: 2021-05
期刊: Electronics
影响因子: 2.9
作者: [Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar]
通讯作者: Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar
Data Analytics for Cyber Risk Analysis Utilizing Cyber Incident Datasets
利用网络事件数据集进行网络风险分析的数据分析
DOI: 10.1109/sieds52267.2021.9483743
发表时间: 2021
期刊: 2021 Systems and Information Engineering Design Symposium (SIEDS
影响因子: --
作者: [Portalatin, Melissa, Keskin, Omer, Malneedi, Sneha, Raza, Owais, Tatar, Unal]
通讯作者: Tatar, Unal
海外基金