The unparalleled scalability and flexibility of cloud computing have fundamentally transformed how businesses manage and store data (Hashizume, 2013). However, security risks and hazards are becoming more and more of a concern as businesses use cloud services. This paper provides an in-depth analysis of the various security concerns that cloud computing infrastructures have to address (Hashizume, 2013). By examining common threats like data breaches, unauthorized access, unsecured interfaces, and shared technological vulnerabilities, this study aims to illustrate the critical importance of proactive security measures in protecting sensitive data (Shaikh, 2011). Through an analysis of network security strategies, identity and access management, encryption technologies, and incident response planning, this paper offers insights into best practices for managing security risks in the cloud (Shaikh, 2011). This paper provides businesses with a road map for enhancing their cloud security.
Scenario analysis is a popular proactive cyber-risk evaluation method to evaluate the enterprise attack-surface. Typically such analysis begin by constructing formal threat models such as of attack tree or attack graph that are then reduced further to analytical models such as of timed automaton or Petri-Net. Note that the development of these attack models is a manual process involving multiple stakeholders. This makes it a tedious, error-prone task that involves many times implicit assumptions by the model developer. Contribution of this paper is a novel approach to cyber-risk evaluation by utilizing log files and Petri-Nets. While the use of Petri-Nets in security modeling is not entirely novel, this paper serves as bridge between formal methods community and cyber-security in its proposed automated tool-chain to perform scenario analysis. Input to our framework is the comma separated log files that is parsed by the python scripts and generates the analytic model of Petri-Net using the popular process mining algorithm, the α-algorithm. Next the Petri-Net model is perturbed altering few transitions signifying the attacker actions. By iteratively performing the reachability analysis over the perturbed model, we analyze the impact of the attacker actions. We demonstrate our work with an e-commerce case study.
Due to their ease of use and accessibility to a vast array of services, mobile applications have become indispensable in our everyday lives. Still, there are more security dangers as a result of the quick spread of mobile apps (Basavala, 2013). This article examines typical vulnerabilities that affect mobile applications and the techniques used to identify and fix them. It concentrates on the vulnerability assessment of mobile applications (Basavala, 2013). This research tries to highlight the significance of protecting mobile apps by an examination of many vulnerability categories, including inadequate encryption, unsafe communication, and insecure data storage (Basavala, 2013). This article offers insight into how developers, security experts, and organizations may proactively detect and mitigate vulnerabilities in mobile apps by going over the tools, methodologies, and best practices for doing vulnerability assessments (He, 2015). In the end, this paper highlights how important it is to have strong security mechanisms in place to secure user data and mobile apps in an increasingly interconnected digital economy (He, 2015).
Cyber-physical system such as automatic metering infrastructure (AMI) are overly complex infrastructures. With myriad stakeholders, real-time constraints, heterogeneous platforms and component dependencies, a plethora of attacks possibilities arise. Despite the best of available technology countermeasures and compliance standards, security practitioners struggle to protect their infrastructures. At the same time, it is important to note that not all attacks are same in terms of their likelihood of occurrence and impact. Hence, it is important to rank the various attacks and perform scenario analysis to have an objective decision on security countermeasures. In this paper, we make a comprehensive security risk analysis of AMI, both qualitatively and quantitatively. Qualitative analysis is performed by ranking the attacks in terms of sensitivity and criticality. Quantitative analysis is done by arranging the attacks as an attack tree and performing Bayesian analysis. Typically, state-of-the-art quantitative security risk analysis suffers from data scarcity. We acknowledge the aforementioned problem and circumvent it by using standard vulnerability database. Different from state-of-the-art surveys on the subject, which captures the big picture, our work is geared to is provide the prioritized baselines in addressing most common and damaging attacks.
Engineering safety-critical infrastructures for continuous operation is a challenging task. With increasingly integration and automation, these systems are overwhelmingly exposed to disruptions - arising from both accidental causes and malicious threats. In this paper, we report on our work on developing quan-titative risk assessment methods to ensue such infrastructures remain resilient to disruptions. Our approach involves building the quantitative domain models to carry: a) continuous risk analysis - estimating the likelihood of system disruption and quantify its damaging impact. b) identify the most crucial system components to keep the system operational. c) dictating optimal incident response strategies. Technically, we model the system in a compositional manner by building and composing stochastic timed automaton of each system component. Along with metrics of interest, these models are fed to the statistical model checker of UPPAAL SMC. Metrics of interest are disruption scenarios in the system model. A scenario is encoded in a variant of temporal logic for its use in the model checker. We use a realistic industrial case-study of steam-boiler system to showcase the methodology.
Advanced persistent threats present significant security challenges due to their customized, stealthy and adaptive nature. Since no generic solution exists to combat advanced persistent threats, the recommended option is to employ information security best practices. While practitioner-oriented security guidelines have been published by the International Organization for Standardization and the U.S. National Institute of Standards and Technology, they cannot be employed in rigorous quantitative analyses required for objective decision making such as choosing countermeasures that balance security, cost and usability. In contrast, game-theoretic approaches, which express the behavior of rational agents that maximize their utility, provide appropriate models for objective decision making. This chapter conducts a critical analysis of several game-theoretic approaches for analyzing advanced persistent threats. Eleven highly-cited, peer-reviewed articles from the research literature are examined in terms of their objectives, features, game models and solutions. The models provide valuable insights into advanced persistent threat behavior, support resource-optimal decision making and can be mapped to the various risk management stages. However, they have some delicate modeling and analysis limitations. The critical analysis exposes the omissions in the literature and points to future research focused on integrating practitioner perspectives in game-theoretic approaches to advance information security risk management.
Modern day industrial control systems are overwhelmingly complex. These systems feature intricate interactions between the cyber and the physical components. At the same time, they need to be trustworthy and deliver their services continuously. Underpinning, a crucial industrial activity to ensure the dependability of such critical systems is through timely maintenance, inspections and repairs. Several strategies exist here: "fix it when it breaks" (reactive maintenance), monitor and maintain a system in pre-established time intervals (preventive maintenance), preventive action based upon detected symptoms of failures condition-based maintenance (CBM), etc. In literature, the question of optimal maintenance frequency have been a subject of intense study. However, most papers, do not take information security aspects into account. This paper provides an automated tool-supported quantitative risk analysis framework, Attack-Fault-Maintenance Trees, AFMTs, that will enable practitioners to make informed choice on: (a) identifying the critical component(s) necessary for uninterrupted systems; (b) a decision support system that will provide informed choices on policy measures, countermeasures and safeguards that will reduce the disruptions; (c) run the "what-if" scenarios to find the optimal trade-offs between system attributes (safety, security, usability and maintenance). The front-end of the tool is a domain-specific language geared to represent the system architecture using graphical-constructs. The back-end of the framework remains hidden to the practitioner. It consists of a mathematical engine based on statistical model-checking techniques. A case study of oil-pipeline is used to demonstrate the efficacy of our framework.
Modern-day industries are complex socio-technical entities. Understanding the risks associated with the operation of such systems requires proper consideration of budget constraints, security expertise and evaluating the effects of legacy services. A relatively newer and unorthodox form of cyber-attacks against such systems are Advanced Persistent Threats (APTs). APTs are resourceful and strategic, aiming at maximum damage by stalling critical services and stealing sensitive information. In this article, we demonstrate how attack trees can be used as a common language to model APT attacks in a practitioner-friendly manner. We do so by modelling three prominent APT attacks, namely Stuxnet, Blackenergy and Triton. Each attack is described in a systematic and structured way following the attack tree modelling language. We show that, because attack trees are compositional models, one can reuse them to model other complex attack scenarios. We illustrate this compositional feature by modelling attacks on an industrial oil-pipeline.
In this journal-first paper, we present an overview of our novel formalism of Attack-Fault-Maintenance Trees (AFMTs). Detailed version of work is available in [3]. AFMTs enable practitioners to quantify the disruption scenarios by answering several safety-security metrics. Alongside, it provides an informed decision on optimal maintenance policies by suggesting preventive component repairs and inspection frequencies. We answer the aforementioned metrics through “what-if” and “scenario analysis”. The models are supported by a graphical friendly tool of PASST. The tool’s front-end is a drawing canvas that provides the different syntactic elements used to design a well-formed AFMT model. The back-end of the tool is based on the statistical-model checking techniques. From the practitioner perspective, once the AFMT is designed and input parameters on component failure, detection rates, inspection rates are provided, the entire analysis can be then done as push-button technology using model-checking techniques
Modern day cyber-infrastructures are critically dependent on each other to provide essential services. Current frameworks typically focus on the risk analysis of an isolated infrastructure. Evaluation of potential disruptions taking the heterogeneous cyber-infrastructures is vital to note the cascading disruption vectors and determine the appropriate interventions to limit the damaging impact. This paper presents a cyber-security risk assessment framework for the interconnected cyber-infrastructures. Our methodology is designed to be comprehensive in terms of accommodating accidental incidents and malicious cyber threats. Technically, we model the functional dependencies between the different architectures using reliability block diagrams (RBDs). RBDs are convenient, yet powerful graphical diagrams, which succinctly describe the functional dependence between the system components. The analysis begins by selecting a service from the many services that are outputted by the synchronized operation of the architectures whose disruption is deemed critical. For this service, we design an attack fault tree (AFT). AFT is a recent graphical formalism that combines the two popular formalisms of attack trees and fault trees. We quantify the attack-fault tree and compute the risk metrics - the probability of a disruption and the damaging impact. For this purpose, we utilize the open source ADTool. We show the efficacy of our framework with an example outage incident.
This paper examines the transition in the cyber-security discipline induced by the ongoing COVID-19 pandemic. Using the classical information retrieval techniques, a more than twenty thousand documents are analyzed for the cyber content. In particular, we build the topic models using the Latent Dirichlet Allocation (LDA) unsupervised machine learning algorithm. The literature corpus is build through a uniform keyword search process made on the scholarly and the non-scholarly platforms filtered through the years 2010-2021. To qualitatively know the impact of COVID-19 pandemic on cyber-security, and perform a trend analysis of key themes, we organize the entire corpus into various (combination of) categories based on time period and whether the literature has undergone peer review process. Based on the weighted distribution of keywords in the aggregated corpus, we identify the key themes. While in the pre-COVID-19 period, the topics of cyber-threats to technology, privacy policy, blockchain remain popular, in the post-COVID-19 period, focus has shifted to challenges directly or indirectly brought by the pandemic. In particular, we observe post-COVID-19 cyber-security themes of privacy in healthcare, cyber insurance, cyber risks in supply chain gaining recognition. Few cyber-topics such as of malware, control system security remain important in perpetuity. We believe our work represents the evolving nature of the cyber-security discipline and reaffirms the need to tailor appropriate interventions by noting the key trends.
This paper performs a bibliometric analysis of the peer-reviewed literature on Advanced Persistent Threats (APTs) taken from 2010–2020. APTs being a complex and tactical attack, require a multi-disciplinary perspective. In this study, we reveal several emerging trends based on 1205 literature papers. We report many popular bibliometric indicators, for example, publication trends, prolific authors, citation analysis, co-author analysis, and publication forums. An important indicator reported in our study is to find common research themes. To do that, we utilize the unsupervised Louvain algorithm. We believe our work will give insights into the current development in APT work, identifying common research themes and promote collaborations between researchers.
Advanced persistent threats (APTs) are different from other computer-based attacks in their target selection, attack technique, and malicious motive. Distinct from script kiddie attacks, these attacks target critical systems to inflict maximum damage, such as to stall critical industrial processes. Standard defenses against APT attack is to deploy security mechanisms that are typically reminiscent of enterprise defense systems such as firewalls, intrusion detection systems, etc. However, given the nature and attack potential of APT attacks, one cannot rely on these security mechanisms alone as they are susceptible to failure, false alarms, and interfere with usability. A yet another problem is to decide on which mechanisms to deploy and at which points to offer maximum coverage against attacks. We believe, given the unique characteristics of APT attacks, one needs a robust and layered defense to protect against APT by timely detection, prevention, mitigation, and emergency plan. One such objective way to determine the countermeasures' efficacy is by modeling and simulating attack behaviour. In this paper, we propose a two-layer framework to analyze the APT attacks. At the top is the domain model of the Enhanced cyber kill chain. We use it to capture the attack phases, techniques, and processes. The bottom layer is the analytic layer of stochastic timed automata derived from the domain model. Key metrics are obtained using a state-of-the-art statistical model - checking techniques. We argue that such a timed analysis can be used to improve the security posture by putting counter-measures at appropriate positions.
The biggest challenge of task scheduling in Fog computing is to satisfy users' dynamic requirements in real‐time with Fog nodes' limited resource capacities. Fog nodes' heterogeneity and an obligation to complete tasks by the deadline while minimizing cost and energy consumption makes the scheduling process more challenging. This article facilitates a deeper understanding of the research issues through a detailed taxonomy and distinguishes significant challenges in existing work. Furthermore, the paper investigates existing solutions for various challenges, presents a meta‐analysis on quality of service parameters and tools used to implement Fog task scheduling algorithms. This systematic review will help potential researchers easily identify specific research problems and future directions to enhance scheduling efficiency.
Attack trees (ATs) are a popular model-based formalism to perform a security risk assessment. The benefits of using AT are numerous: graphical top-down representation of multi-stage attack scenarios, several analysis frameworks, and many supporting tools. The current practice of constructing an attack tree for a given system is using the rules-of-thumb. Though this process is flexible, in the absence of a template, it is non-standardized. Hence it is tedious and may result in contention between the stakeholders due to individual idiosyncrasies. To address these limitations, in this paper, we develop an AT template. We meticulously design the template by performing a literature survey of the industry-size ATs and extract the meta-categories used to build them. The AT template is then structured into layers by the systematic question-answering methodology of Potts et al. Each successive layer in our template is a refinement of the previous layer, adding more details. We link the AT template to standard threat databases. Thus, our template guides the practitioner on narrowing to the appropriate attack vectors. An important question here is how to keep the AT template flexible, given the diversity of context and system variables. To address the question, we use a feature diagram to represent the AT categories. We used the AT template to gain practical experience over a hypothetical case study of smart meters (not part of the paper). Based on our experience, we suggest future research directions.
Interconnected infrastructures are complex due to their temporal evolution, component dependencies and dynamic interdependencies, coupled with the presence of adversaries. Much research has focused on safety and security risk assessments of isolated infrastructures. However, extending these techniques to interconnected infrastructures is infeasible due to their complex interdependencies and the lack of generic modeling tools. This chapter presents a framework for modeling and analyzing interconnected infrastructures. The framework has a two layers. One is the higher modeling layer that expresses the functional dependencies of infrastructures, where each infrastructure is refined to capture component-level disruptions and is represented using a novel combination of dynamic reliability block diagrams and attack-fault trees. The other is the lower analysis layer based on stochastic timed automata that serves as a semantic framework for the higher layer. While the higher layer graphically represents complex dependencies and interdependencies, and temporal and cascading disruption scenarios, the lower analysis layer provides a rigorous foundation for investigating the relationships using formal verification, in particular, statistical model checking. The lower layer also provides a flexible means for incorporating quantitative system attributes such as probability, time and cost. The efficacy of the framework is demonstrated using a real disruption scenario involving interconnected electric power and industrial communications networks, where an analyst can identify weak links, evaluate alternative protection measures and make transparent decisions about risk management investments.
“The relationship between environment and security has been under consideration since the 1980s mainly by two groups: 1. The environmental policy community, addressing the security implication of environmental change and security, and 2. The security community, looking at new definitions of national security, particularly in the post-cold war era. It was soon acknowledged that global impacts of for example environmental change, the depletion of the ozone layer and transboundary pollution, have clear security implications. This in turn made the military authorities to re-evaluate the security dimensions of environmental issues. Security was traditionally seen as a synonym for national security with two main objectives: 1. To preserve the territorial integrity of the state and 2. To maintain the preferred from the government, by political and military means. When political scientists took up the environmental aspects of security, they defined environment impacts as being part of the security issue. This approach attempted to re-define the concept of national security completely. In the early 1980s the Independent Commission on Security and Disarmament Issue (ICSDI) developed and introduced the concept of common security, giving the idea of national security a broader perspective. Additional to the traditional security aspects, other non-traditional threats to security , e.g. economic decline, social and political instability, ethnic rivalries and traditional dispute, international terrorism, money laundering and drug trafficking as well as environmental stress, have been incorporated. In recent years environmental security has been understood extensively, included human, physical, social and economic well being, giving the scope hardly any limitation for interpretations. At present, however, there is no consensus on a clear definition of environmental security. For the purpose of this paper, the scope of the issue is limited on how environmental impacts may affect conflicts, rather than security as such. In this respect, environmental security has basically a main dimensions: environmental stress may be a cause as well as a result of a conflict.”
Attack trees (ATs) are a popular formalism for security analysis, and numerous variations and tools have been developed around them. These were mostly developed independently, and offer little interoperability or ability to combine various AT features. We present ATTop, a software bridging tool that enables automated analysis of ATs using a model-driven engineering approach. ATTop fulfills two purposes: 1. It facilitates interoperation between several AT analysis methodologies and resulting tools (e.g., ATE, ATCalc, ADTool 2.0), 2. it can perform a comprehensive analysis of attack trees by translating them into timed automata and analyzing them using the popular model checker Uppaal, and translating the analysis results back to the original ATs. Technically, our approach uses various metamodels to provide a unified description of AT variants. Based on these metamodels, we perform model transformations that allow to apply various analysis methods to an AT and trace the results back to the AT domain. We illustrate our approach on the basis of a case study from the AT literature.
We introduce a formal specification language locks, that allow security practitioners to express as well as compose security goals in a convenient manner. locks supports the specification of the most common security properties over generic attributes, both for qualitative and quantitative goals. To make our language independent of a specific security framework, we evaluate locks over a generic attack model, namely the structural attack model (sam), which over-arches the most prominent graphical threat models. Furthermore, we equip our language with a concise grammar, type rules and denotational semantics, thus laying the foundations of an automated tool. We take a number of informal security goals from the literature and show how they can be formally expressed in our language.