CRII: SaTC: Graph-based Probabilistic Cyber Risk Modeling
CRII: SaTC: Graph-based Probabilistic Cyber Risk Modeling
批准号:
1948261
负责人:
Unal Tatar
金额:
$17.5万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-04-01 至 2023-03-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Cybersecurity risk analysis is one of the primary tools for managing the consequences of cyber incidents. There are several limitations of the current cybersecurity risk analysis methods. First, cyber risk is often treated as an information technology problem rather than a vital part of enterprise risk management. Another deficiency of the cyber risk analysis methods is the insufficiency of the utilized metrics to support investment decisions. Qualitative metrics and operational terms are often used as cyber risk indicators rather than quantified financial measures that guide investment decisions. Besides these, the lack of quantification of how investments in specific controls change risk level is another limitation of the current cyber risk analysis methods. This project aims to develop a probabilistic quantitative cybersecurity risk analysis model to relate asset-level risk to organizational-level risk and supply chain level risk to respond to the aforementioned deficiencies of the current cyber risk analysis methods. The results from this research enables effective and accurate supply-chain cyber risk assessment, which, in turn, increases economic competitiveness by enabling more effective and efficient mitigation of cyber risks and well-informed cybersecurity investments. The project provides training opportunities for students at different levels and from under-represented groups. Education materials developed in the project will be shared nationally through the National Security Agency supported CLARK repository of cybersecurity learning objects.The main research problem of this study is what kind of a probabilistic quantitative cybersecurity risk analysis model can be developed to relate asset-level risk to organizational-level risk and supply chain level risk. This project employs probabilistic attack graphs, which are based on known vulnerabilities in computer software and network topologies. The dynamic risk assessment capabilities are augmented in the attack graph using Bayesian Belief Networks. A graph-theoretical functional dependency model is also developed to model the ripple effects of cyber-attacks on enterprise missions to failures in supply-chains. Simulations and sensitivity analysis are conducted on a smart grid testbed to validate the developed risk analysis model.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Scoring Cyber Vulnerabilities based on Their Impact on Organizational Goals *
根据网络漏洞对组织目标的影响对网络漏洞进行评分 *
DOI:
10.1109/sieds52267.2021.9483741
发表时间:
2021
期刊:
2021 Systems and Information Engineering Design Symposium (SIEDS
影响因子:
--
作者:
[Keskin, Omer, Gannon, Nick, Lopez, Brian, Tatar, Unal]
通讯作者:
Tatar, Unal
Managing Physical and Economic Risk for Systems with Multidirectional Network Interdependencies
管理具有多向网络相互依赖性的系统的物理和经济风险
DOI:
10.1111/risa.13824
发表时间:
2022
期刊:
Risk Analysis
影响因子:
3.8
作者:
[Tatar, Unal, Santos, Joost R., Thekdi, Shital A.]
通讯作者:
Thekdi, Shital A.
DOI:
10.3390/electronics10101168
发表时间:
2021-05
期刊:
Electronics
影响因子:
2.9
作者:
[Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar]
通讯作者:
Omer F. Keskin;Kevin Matthe Caramancion;Irem Tatar;Owais Raza;Unal Tatar
Data Analytics for Cyber Risk Analysis Utilizing Cyber Incident Datasets
利用网络事件数据集进行网络风险分析的数据分析
DOI:
10.1109/sieds52267.2021.9483743
发表时间:
2021
期刊:
2021 Systems and Information Engineering Design Symposium (SIEDS
影响因子:
--
作者:
[Portalatin, Melissa, Keskin, Omer, Malneedi, Sneha, Raza, Owais, Tatar, Unal]
通讯作者:
Tatar, Unal
海外基金