Abstract
Attacks on organisations today explore many different layers, including buildings infrastructure, IT infrastructure, and human factor – the physical, virtual, and social layer. Identifying possible attacks, understanding their impact, and attributing their origin and contributing factors is difficult. Recently, system models have been used for automatically identifying possible attacks on the modelled organisation. The generated attacks consider all three layers, making the contribution of building infrastructure, computer infrastructure, and humans (insiders and outsiders) explicit. However, this contribution is only visible in the attack trees as part of the performed steps; it cannot be mapped back to the model directly since the actions usually involve several elements (attacker and targeted actor or asset). Especially for large attack trees, understanding the relations between several model components quickly results in a large quantity of interrelations, which are hard to grasp. In this work we present several approaches for visualising attributes of attacks such as likelihood of success, impact, and required time or skill level. The resulting visualisations provide a link between attacks on an organisations and the contribution of parts of an organisation to the attack and its impact.
Original language | English |
---|---|
Title of host publication | Proceedings of the 21st Nordic Conference on Secure IT Systems (NordSec 2016) |
Publisher | Springer |
Publication date | 2016 |
Pages | 54-66 |
ISBN (Print) | 978-3-319-47559-2 |
ISBN (Electronic) | 978-3-319-47560-8 |
DOIs | |
Publication status | Published - 2016 |
Event | 21st Nordic Conference on Secure IT Systems - Oulu, Finland Duration: 2 Nov 2016 → 4 Nov 2016 Conference number: 21 |
Conference
Conference | 21st Nordic Conference on Secure IT Systems |
---|---|
Number | 21 |
Country/Territory | Finland |
City | Oulu |
Period | 02/11/2016 → 04/11/2016 |
Series | Lecture Notes in Computer Science |
---|---|
Volume | 10014 |
ISSN | 0302-9743 |