SCyTAG: Scalable Cyber-Twin for Threat-Assessment Based on Attack Graphs
David Tayouri, Elad Duani, Abed Showgan, Ofir Manor, Ortal Lavi, Igor Podoski, Miro Ohana, Yuval Elovici, Andres Murillo, Asaf Shabtai, Rami Puzis

TL;DR
SCyTAG is a scalable framework that creates minimal cyber twins from attack graphs to efficiently assess cyber threats, reducing resource needs while maintaining high fidelity in threat emulation.
Contribution
It introduces a novel multi-step method to generate minimal cyber twins from attack graphs, enabling scalable and accurate threat impact assessment.
Findings
Reduces network component requirements by up to 85%.
Halves the resources needed for attack emulation.
Maintains high fidelity in threat scenario testing.
Abstract
Understanding the risks associated with an enterprise environment is the first step toward improving its security. Organizations employ various methods to assess and prioritize the risks identified in cyber threat intelligence (CTI) reports that may be relevant to their operations. Some methodologies rely heavily on manual analysis (which requires expertise and cannot be applied frequently), while others automate the assessment, using attack graphs (AGs) or threat emulators. Such emulators can be employed in conjunction with cyber twins to avoid disruptions in live production environments when evaluating the highlighted threats. Unfortunately, the use of cyber twins in organizational networks is limited due to their inability to scale. In this paper, we propose SCyTAG, a multi-step framework that generates the minimal viable cyber twin required to assess the impact of a given attack…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Software-Defined Networks and 5G · Network Security and Intrusion Detection
