A Layered Graphical Model for Cloud Forensic Mission Attack Impact Analysis - Advances in Digital Forensics XIV
Conference Papers Year : 2018

A Layered Graphical Model for Cloud Forensic Mission Attack Impact Analysis

Abstract

Cyber attacks on the systems that support an enterprise’s mission can significantly impact its objectives. This chapter describes a layered graphical model designed to support forensic investigations by quantifying the mission impacts of cyber attacks. The model has three layers: (i) an upper layer that models operational tasks and their interdependencies that fulfill mission objectives; (ii) a middle layer that reconstructs attack scenarios based on the interrelationships of the available evidence; and (iii) a lower level that uses system calls executed in upper layer tasks in order to reconstruct missing attack steps when evidence is missing. The graphs constructed from the three layers are employed to compute the impacts of attacks on enterprise missions. The National Vulnerability Database – Common Vulnerability Scoring System scores and forensic investigator estimates are used to compute the mission impacts. A case study is presented to demonstrate the utility of the graphical model.
Fichier principal
Vignette du fichier
472401_1_En_15_Chapter.pdf (362.34 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-01988841 , version 1 (22-01-2019)

Licence

Identifiers

Cite

Changwei Liu, Anoop Singhal, Duminda Wijesekera. A Layered Graphical Model for Cloud Forensic Mission Attack Impact Analysis. 14th IFIP International Conference on Digital Forensics (DigitalForensics), Jan 2018, New Delhi, India. pp.263-289, ⟨10.1007/978-3-319-99277-8_15⟩. ⟨hal-01988841⟩
63 View
72 Download

Altmetric

Share

More