Consistent and Compatible Modelling of Cyber Intrusions and Incident Response Demonstrated in the Context of Malware Attacks on Critical Infrastructure
Peter Maynard, Yulia Cherdantseva, Avi Shaked, Pete Burnap, Arif Mehmood

TL;DR
This paper presents a method to unify intrusion models and incident response playbooks using a common framework, enhancing cyber attack analysis and response for critical infrastructure.
Contribution
It introduces a novel representation of attack trees within the Security Modelling Framework and a tool to convert attack models into IR-compatible formats.
Findings
Enhanced intrusion models with better integration into IR playbooks
Tighter coupling between threat modelling and incident response
Novel insights into attack analysis and response strategies
Abstract
Cyber Security Incident Response (IR) Playbooks are used to capture the steps required to recover from a cyber intrusion. Individual IR playbooks should focus on a specific type of incident and be aligned with the architecture of a system under attack. Intrusion modelling focuses on a specific potential cyber intrusion and is used to identify where and what countermeasures are needed, and the resulting intrusion models are expected to be used in effective IR, ideally by feeding IR Playbooks designs. IR playbooks and intrusion models, however, are created in isolation and at varying stages of the system's lifecycle. We take nine critical national infrastructure intrusion models - expressed using Sequential AND Attack Trees - and transform them into models of the same format as IR playbooks. We use Security Modelling Framework for modelling attacks and playbooks, and for demonstrating the…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Network Security and Intrusion Detection · Smart Grid Security and Resilience
