中文
相关论文

相关论文: URSID: Using formalism to Refine attack Scenarios …

200 篇论文

Cyber threat intelligence (CTI) encoded in STIX and structured according to the MITRE ATT&CK framework has become a global reference for describing adversary behavior. However, ATT&CK was designed as a descriptive knowledge base rather than…

This paper introduces a novel complexity-informed approach to cybersecurity management, addressing the challenges found within complex cyber defences. We adapt and extend the complexity theory to cybersecurity and develop a quantitative…

密码学与安全 · 计算机科学 2025-01-28 Lampis Alevizos

The ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network…

密码学与安全 · 计算机科学 2022-06-22 Lukáš Sadlek , Pavel Čeleda , Daniel Tovarňák

We apply formal methods to lay and streamline theoretical foundations to reason about Cyber-Physical Systems (CPSs) and cyber-physical attacks. We focus on %a formal treatment of both integrity and DoS attacks to sensors and actuators of…

密码学与安全 · 计算机科学 2017-04-24 Ruggero Lanotte , Massimo Merro , Riccardo Muradore , Luca Viganò

The concept of scenario and its many qualifications -- specifically logical and abstract scenarios -- have emerged as a foundational element in safeguarding automated driving systems. However, the original linguistic definitions of the…

机器人学 · 计算机科学 2025-04-08 Christian Neurohr , Lukas Westhofen , Tjark Koopmann , Eike Möhlmann , Eckard Böde , Axel Hahn

Cyber deception allows compensating the late response of defenders countermeasures to the ever evolving tactics, techniques, and procedures (TTPs) of attackers. This proactive defense strategy employs decoys resembling legitimate system…

密码学与安全 · 计算机科学 2024-10-17 Marco Zambianco , Claudio Facchinetti , Domenico Siracusa

Surgical procedures are often not "standardised" (i.e., defined in a unique and unambiguous way), but rather exist as implicit knowledge in the minds of the surgeon and the surgical team. This reliance extends to pre-surgery planning and…

密码学与安全 · 计算机科学 2024-08-12 Ioana Sandu , Rita Borgo , Prokar Dasgupta , Ramesh Thurairaja , Luca Viganò

Organizations employ various adversary models in order to assess the risk and potential impact of attacks on their networks. Attack graphs represent vulnerabilities and actions an attacker can take to identify and compromise an…

密码学与安全 · 计算机科学 2022-08-12 David Tayouri , Nick Baum , Asaf Shabtai , Rami Puzis

The power grid is a critical infrastructure essential for public safety and welfare. As its reliance on digital technologies grows, so do its vulnerabilities to sophisticated cyber threats, which could severely disrupt operations. Effective…

密码学与安全 · 计算机科学 2024-12-10 Omer Sen , Bozhidar Ivanov , Christian Kloos , Christoph Zol_ , Philipp Lutat , Martin Henze , Andreas Ulbig

Security attacks are hard to understand, often expressed with unfriendly and limited details, making it difficult for security experts and for security analysts to create intelligible security specifications. For instance, to explain Why…

密码学与安全 · 计算机科学 2014-10-17 Muhammad Sabir Idrees , Yves Roudier , Ludovic Apvrille

The reported work points at developing a practical approach for power transmission planners to secure power networks from potential deliberate attacks. We study the interaction between a system planner (defender) and a rational attacker who…

系统与控制 · 电气工程与系统科学 2019-12-13 Hamzeh Davarikia , Masoud Barati , Mustafa Al-Assad , Yupo Chan

This works considers challenges of building and usage a formal knowledge base (model), which unites the ATT&CK, CAPEC, CWE, CVE security enumerations. The proposed model can be used to learn relations between attack techniques, attack…

密码学与安全 · 计算机科学 2021-12-09 Andrei Brazhuk

In recent cyber attacks, credential theft has emerged as one of the primary vectors of gaining entry into the system. Once attacker(s) have a foothold in the system, they use various techniques including token manipulation to elevate the…

密码学与安全 · 计算机科学 2022-11-30 Jaimandeep Singh , Chintan Patel , Naveen Kumar Chaudhary

Recent progress in (Large) Language Models (LMs) has enabled the development of autonomous LM-based agents capable of executing complex tasks with minimal supervision. These agents have started to be integrated into systems with significant…

密码学与安全 · 计算机科学 2026-03-04 Federico Villa , F. Betül Durak , Tadayoshi Kohno , Tapdig Maharramli , Franziska Roesner

The ability to analyze network threats is very important in security research. Traditional approaches, involving sandboxing technology are limited to simulating a single host, missing local network attacks. This issue is addressed by…

密码学与安全 · 计算机科学 2020-07-17 Francisc Moldovan , Ciprian Oprisa

Attack graphs are a tool for analyzing security vulnerabilities that capture different and prospective attacks on a system. As a threat modeling tool, it shows possible paths that an attacker can exploit to achieve a particular goal.…

We focus in this paper on the problem of configuring and managing network security devices, such as Firewalls, Virtual Private Network (VPN) tunnels, and Intrusion Detection Systems (IDSs). Our proposal is the following. First, we formally…

密码学与安全 · 计算机科学 2009-05-12 Stere Preda , Nora Cuppens-Boulahia , Frederic Cuppens , Joaquin Garcia-Alfaro , Laurent Toutain

Attack graphs provide a representation of possible actions that adversaries can perpetrate to attack a system. They are used by cybersecurity experts to make decisions, e.g., to decide remediation and recovery plans. Different approaches…

密码学与安全 · 计算机科学 2022-02-09 Kéren Saint-Hilaire , Frédéric Cuppens , Nora Cuppens , Joaquin Garcia-Alfaro

Responses to disastrous events are a challenging problem, because of possible damages on communication infrastructures. For instance, after a natural disaster, infrastructures might be entirely destroyed. Different network paradigms were…

分布式、并行与集群计算 · 计算机科学 2020-04-30 Aznam Yacoub

Current threat models typically consider all possible ways an attacker can penetrate a system and assign probabilities to each path according to some metric (e.g. time-to-compromise). In this paper we discuss how this view hinders the…

密码学与安全 · 计算机科学 2018-01-16 Luca Allodi , Sandro Etalle