conference-paper

Threat Evaluation of Enterprise Utilizations via Graphical Modeling

Research footprint

At a glance

Citations
0
References
14
Comments
0
Paper overview

Abstract

Studying cyber resilience has proved to be a difficult technological obstacle. Numerous case studies have been performed to assess the cyber resilience of enterprise business systems using attack graphs. removing the assets level, service resource, activity surface for the commercial processes, etc.. from a generic business enterprise system is challenging for automation since here is where task dependencies and formal vulnerability description meet to build attack graphs. We provide a model for threat analysis of a company based on a specified group of vulnerabilities spread across many layers of business operations. First, we collect the company's task dependencies from its process flow (BPMN), and afterwards we retrieve the hierarchy dependencies that includes the asset-, service-, and process management components. We infer a logical concept of security risk transmission from the graphical reliance structure and the susceptibility criteria in order to build MulVAL multi-step, multi-stage attacks. The MulVAL-created attack graph is imported into the graph database Neo4J to provide online/real-time dynamic security risk dissemination analysis. In addition, we detail how the system's risk analysis may be achieved with the inclusion of certain parameters. Since we took an all-encompassing approach, threat analysis is now flexible and extensible. We show how our approach can be applied to larger systems and how graphical modeling can be used to investigate risk evaluations for enterprise software. In turn, this enables the use of a wide range of mitigation techniques for reducing the spread of threats and vulnerabilities.

Record transparency

Publication details

DOI
10.1109/icacite57410.2023.10182547
OpenAlex
W4385213813
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.