Simulation Modeling Cyber Threats, Risks, and Prevention Costs

James E. Lerums, La'Reshia D. Poe, J. E. Dietz
{"title":"Simulation Modeling Cyber Threats, Risks, and Prevention Costs","authors":"James E. Lerums, La'Reshia D. Poe, J. E. Dietz","doi":"10.1109/EIT.2018.8500240","DOIUrl":null,"url":null,"abstract":"Money spent on cybersecurity doesn't easily translate into an increase in an organization's operational success or increase in revenues and profitability. However, an organization suffering from a cyber-attack could incur significant additional costs which can detrimentally impact an organization trivially or catastrophically. This paper introduces a simulation model for analyzing the effectiveness versus cost of cyber security options. The outcomes of this study is a simulation model using state charts capable of running a configurable attack scenario several times for a specified enterprise network and threat. Given publicly available information our findings after running a phishing attack on a departmental workstation with the internal network's domain controller as the final target revealed that the overall success rate of a phishing attack reaching any node in a “generic enterprise” architecture is 20%, with less than 0% of the attacks reaching the intended target.","PeriodicalId":188414,"journal":{"name":"2018 IEEE International Conference on Electro/Information Technology (EIT)","volume":"90 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE International Conference on Electro/Information Technology (EIT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/EIT.2018.8500240","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Money spent on cybersecurity doesn't easily translate into an increase in an organization's operational success or increase in revenues and profitability. However, an organization suffering from a cyber-attack could incur significant additional costs which can detrimentally impact an organization trivially or catastrophically. This paper introduces a simulation model for analyzing the effectiveness versus cost of cyber security options. The outcomes of this study is a simulation model using state charts capable of running a configurable attack scenario several times for a specified enterprise network and threat. Given publicly available information our findings after running a phishing attack on a departmental workstation with the internal network's domain controller as the final target revealed that the overall success rate of a phishing attack reaching any node in a “generic enterprise” architecture is 20%, with less than 0% of the attacks reaching the intended target.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
网络威胁、风险和预防成本的仿真建模
花在网络安全上的钱并不容易转化为组织运营成功的增加或收入和盈利能力的增加。然而,遭受网络攻击的组织可能会产生显著的额外成本,这可能会对组织造成轻微或灾难性的不利影响。本文介绍了一个仿真模型,用于分析网络安全选项的有效性与成本。这项研究的结果是一个使用状态图的仿真模型,能够针对特定的企业网络和威胁多次运行可配置的攻击场景。在以内部网络域控制器为最终目标的部门工作站上运行网络钓鱼攻击后,根据公开信息,我们的研究结果显示,到达“通用企业”架构中任何节点的网络钓鱼攻击的总体成功率为20%,达到预定目标的攻击不到0%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Developing A Dynamic Queueing Model for The Airport Check-in Process Issues and Challenges in VANET Routing Protocols Depiction of a Circulated Double Psi-Shaped Microstrip Antenna for Ku-Band Satellite Applications A Generic Approach CNN-Based Camera Identification for Manipulated Images Intelligent System Demonstrator for Secure Luggage Handling
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1