Risk-Based models of attacker behavior in cybersecurity

  • Authors:
  • Si Li;Ryan Rickert;Amy Sliva

  • Affiliations:
  • College of Computer and Information Science, Northeastern University;College of Computer and Information Science, Northeastern University;College of Computer and Information Science, Northeastern University

  • Venue:
  • SBP'13 Proceedings of the 6th international conference on Social Computing, Behavioral-Cultural Modeling and Prediction
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Even as reliance on information and communication technology networks continues to grow, and their potential security vulnerabilities become a greater threat, very little is known about the humans who perpetrate cyber attacks--what are their strategies, resources, and motivations? We present a new framework for modeling such cyber attackers. Utilizing observable information (i.e., network alerts, security implementations, systems logs), we can characterize attackers based on the risk they are willing to incur and delineate them based on skill level. These classifications can facilitate decision-making and resource allocation to counteract cybersecurity incidents. We look at two specific models of attacker risk and discuss empirical results from a prototype implementation of this modeling framework using real-world network data.