Session-level Adversary Intent-Driven Cyberattack Simulator | IEEE Conference Publication | IEEE Xplore

Session-level Adversary Intent-Driven Cyberattack Simulator


Abstract:

Recognizing the need for proactive analysis of cyber adversary behavior, this paper presents a new event-driven simulation model and implementation to reveal the efforts ...Show More

Abstract:

Recognizing the need for proactive analysis of cyber adversary behavior, this paper presents a new event-driven simulation model and implementation to reveal the efforts needed by attackers who have various entry points into a network. Unlike previous models which focus on the impact of attackers' actions on the defender's infrastructure, this work focuses on the attackers' strategies and actions. By operating on a request-response session level, our model provides an abstraction of how the network infrastructure reacts to access credentials the adversary might have obtained through a variety of strategies. We present the current capabilities of the simulator by showing three variants of Bronze Butler APT on a network with different user access levels.
Date of Conference: 14-16 September 2020
Date Added to IEEE Xplore: 06 October 2020
ISBN Information:
Print on Demand(PoD) ISSN: 1550-6525
Conference Location: Prague, Czech Republic

Contact IEEE to Subscribe

References

References is not available for this document.