Session-level Adversary Intent-Driven Cyberattack Simulator

2020 IEEE/ACM 24th International Symposium on Distributed Simulation and Real Time Applications (DS-RT)(2020)

引用 1|浏览0
暂无评分
摘要
Recognizing the need for proactive analysis of cyber adversary behavior, this paper presents a new event-driven simulation model and implementation to reveal the efforts needed by attackers who have various entry points into a network. Unlike previous models which focus on the impact of attackers' actions on the defender's infrastructure, this work focuses on the attackers' strategies and actions. By operating on a request-response session level, our model provides an abstraction of how the network infrastructure reacts to access credentials the adversary might have obtained through a variety of strategies. We present the current capabilities of the simulator by showing three variants of Bronze Butler APT on a network with different user access levels.
更多
查看译文
关键词
DEVS,cybersecurity,adversary behavior,APT
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要