课题基金 / 基金详情

The Cost of Exploitation: A comparative view of socio-technical factors across varying degrees of attack complexity

The Cost of Exploitation: A comparative view of socio-technical factors across varying degrees of attack complexity
利用成本:不同攻击复杂程度的社会技术因素的比较
批准号:
1931272
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
在一个典型的网络安全风险评估中,防御者会假设对手可能会攻击有问题的实体,例如,这是一个业余爱好者,黑客,甚至是民族国家行为者。与其依赖于这种模糊的假设,防御者可以通过量化对手为了在时间、金钱和技术专长方面妥协一个系统而可能产生的成本来更好地了解情况。一旦攻击成本被量化,防御者就可以更好地了解他们可能面临的攻击类型,并应用安全控制来适应他们的风险偏好。近年来,大规模的网络攻击变得越来越普遍,无论是为了金钱利益,破坏潜力还是间谍活动。这些网络攻击中的一个共同主题是使用基于人类(社会)和基于技术(技术)的技术来造成最大的影响。2013年对塔吉特的攻击导致4000万信用卡和借记卡账户被盗,这是通过包含恶意软件的钓鱼电子邮件发起的,然后才进行进一步的妥协和更复杂的技术攻击。这表明,为了准确地计算利用成本,了解社交攻击的成本与了解技术攻击的成本一样重要。这些大规模的社会技术网络攻击也出现在工业控制系统(ICS)上,特别是2015年对乌克兰Kyivoblenergo的攻击和2010年臭名昭着的Stuxnet,两者都分别使用了社交技术,鱼叉式网络钓鱼和恶意软件支持的USB记忆棒,并且都使用了与工业控制系统有关的利基技术攻击。在工业控制系统领域,由于所需的利基知识和更难以破译网络上的节点,开发成本,特别是技术专长,可能会大大加剧。为了最好地探索开发成本,理解如何以通用的非上下文特定方式实现开发将是第一步。这将允许以控制变量的方式进行更广泛的规模,以比较更复杂的ICS环境。研究可能会通过文献综述和与信息安全从业人员的接触进行,这些从业人员既扮演攻击技术和复杂性信息的进攻角色,也扮演感知攻击影响和风险的防御角色。这项工作可能会导致一个度量,框架,或可能是一个工具,将提供估计的成本利用一个给定的系统,提供背景,以帮助更好地评估风险,在IT和ICS环境。最后,这种度量标准、框架或工具的开发需要进行评估,这可以通过将其应用于实际环境来完成,以便计算风险评估的预期开发成本。
英文摘要
In a typical assessment for cyber security risk a defender would make an assumption of adversaries likely to attack the entity in question whether this be, for example, an amateur, hacktivist or even nation-state actor. Rather than rely on this ambiguous assumption the defender would be better informed through quantifying the cost an adversary would incur in order to compromise a system in relation to time, money, and technical expertise. Once cost of exploitation is quantified, the defender may better understand the type of advisories they are likely to face, and apply security controls to fit their risk appetite.In recent years large scale cyber attacks have become increasingly prevalent whether for monetary gains, destructive potential, or espionage. One common theme among many of these cyber attacks is the use of joint human based (social) and technology based (technical) techniques to cause the most impact. The attack on Target in 2013 which saw 40 million credit and debit card accounts stolen was instigated through a phishing email containing malware, before further compromise and more complex technical based attacks were employed. This shows that for the cost of exploitation to be accurate, understanding the cost of social attacks is just as crucial as understanding the cost of technical attacks. These large scale socio-technical cyber attacks are being seen too on industrial control systems (ICS), notably the 2015 attack on the Ukranian Kyivoblenergo and the infamous Stuxnet of 2010, both of which utilised social techniques, spear phishing and malware enabled USB sticks respectively, and both used niche technical attacks pertaining to industrial control systems. In the realm of industrial control systems the cost of exploitation, particularly technical expertise, could be greatly exacerbated due to the niche knowledge required and more difficult to decipher nodes on the networks.To best explore the cost of exploitation, understanding how exploitation is achieved in a generic non-context specific manner would be the initial step. This would allow for a much broader scale in the way of a control variable by which to compare the more complex ICS environment. Research would likely be carried out through literature reviews and engagement with information security practitioners in both offensive roles for information on attack techniques and complexity, and defensive roles for perceived impact and risk of attacks. This work could lead to a metric, framework, or possibly a tool which would provide the estimated cost of exploitation for a given system, providing context to aid in better assessing risk in both IT and ICS environments. Finally the development of such a metric, framework, or tool would require evaluation, this could be done through its application to live environments in order to calculate the expected cost of exploitation towards the risk assessment.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金