混合风险分析框架

M. Zharikova, S. Pickl
{"title":"混合风险分析框架","authors":"M. Zharikova, S. Pickl","doi":"10.54941/ahfe1002850","DOIUrl":null,"url":null,"abstract":"Changes within the worldwide security environment proceed to challenge\n our ability to comprehend and react to the constantly changing hybrid\n threats that are becoming more diverse, emanating from a wide range of\n actors who are enabled by technology. Actors can wield an array of means and\n ways to further their security interests at the expense of a target and are\n able to do so without being identified.Developing proper situational\n awareness is a first and crucial step on the road to achieving better\n protection against hybrid threats. Here we propose a novel framework for\n hybrid risk analysis that enables the better understanding of operations of\n the adversary before their taking place.The idea of the framework is based\n on the model of hybrid operations, which combine the elements of space,\n time, objects at risk, goals, and actors into a single structure - a\n hyper-forest of multi-trees.Taking into account that hybrid operations are\n carried out according to certain scenarios characterized by repeatability of\n tools in relation to certain goals, we propose using case-based reasoning\n approach based on calculating the dynamic similarity of the information\n structure of ongoing attack to retrospective sequences of hybrid attacks for\n which the goals, tools, and methods are known. Retrospective data is stored\n in the case base.The proposed framework combines several models and methods,\n the main of which are the multi-tree model of hybrid attack representation,\n spatially distributed model of hybrid attack distribution, and the method\n for hybrid risk analysis. The method for hybrid risk analysis is based on\n two additional models such as vulnerability model and consequences\n assessment model that are developed for each type of object at risk.The\n suggested framework for hybrid risk analysis offers a better comprehension\n of adversary operations prior to them occurring and aids in formulating an\n appropriate reaction to the changing scenario.","PeriodicalId":269162,"journal":{"name":"Proceedings of the 6th International Conference on Intelligent Human Systems Integration (IHSI 2023) Integrating People and Intelligent Systems, February 22–24, 2023, Venice, Italy","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"A Framework for Hybrid Risk Analysis\",\"authors\":\"M. Zharikova, S. Pickl\",\"doi\":\"10.54941/ahfe1002850\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Changes within the worldwide security environment proceed to challenge\\n our ability to comprehend and react to the constantly changing hybrid\\n threats that are becoming more diverse, emanating from a wide range of\\n actors who are enabled by technology. Actors can wield an array of means and\\n ways to further their security interests at the expense of a target and are\\n able to do so without being identified.Developing proper situational\\n awareness is a first and crucial step on the road to achieving better\\n protection against hybrid threats. Here we propose a novel framework for\\n hybrid risk analysis that enables the better understanding of operations of\\n the adversary before their taking place.The idea of the framework is based\\n on the model of hybrid operations, which combine the elements of space,\\n time, objects at risk, goals, and actors into a single structure - a\\n hyper-forest of multi-trees.Taking into account that hybrid operations are\\n carried out according to certain scenarios characterized by repeatability of\\n tools in relation to certain goals, we propose using case-based reasoning\\n approach based on calculating the dynamic similarity of the information\\n structure of ongoing attack to retrospective sequences of hybrid attacks for\\n which the goals, tools, and methods are known. Retrospective data is stored\\n in the case base.The proposed framework combines several models and methods,\\n the main of which are the multi-tree model of hybrid attack representation,\\n spatially distributed model of hybrid attack distribution, and the method\\n for hybrid risk analysis. The method for hybrid risk analysis is based on\\n two additional models such as vulnerability model and consequences\\n assessment model that are developed for each type of object at risk.The\\n suggested framework for hybrid risk analysis offers a better comprehension\\n of adversary operations prior to them occurring and aids in formulating an\\n appropriate reaction to the changing scenario.\",\"PeriodicalId\":269162,\"journal\":{\"name\":\"Proceedings of the 6th International Conference on Intelligent Human Systems Integration (IHSI 2023) Integrating People and Intelligent Systems, February 22–24, 2023, Venice, Italy\",\"volume\":\"7 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"1900-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Proceedings of the 6th International Conference on Intelligent Human Systems Integration (IHSI 2023) Integrating People and Intelligent Systems, February 22–24, 2023, Venice, Italy\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.54941/ahfe1002850\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 6th International Conference on Intelligent Human Systems Integration (IHSI 2023) Integrating People and Intelligent Systems, February 22–24, 2023, Venice, Italy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.54941/ahfe1002850","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

全球安全环境的变化继续挑战我们理解和应对不断变化的混合威胁的能力,这些威胁正变得越来越多样化,来自技术支持的各种行动者。行为者可以运用一系列手段和方式以牺牲目标为代价来促进其安全利益,并且能够在不被识别的情况下这样做。发展适当的态势感知是实现更好地防御混合威胁的第一步,也是至关重要的一步。在这里,我们提出了一种新的混合风险分析框架,可以在对手的行动发生之前更好地理解他们。该框架的思想基于混合操作模型,该模型将空间、时间、风险对象、目标和参与者等元素组合到一个单一结构中——一个多树的超级森林。考虑到混合操作是根据与特定目标相关的工具可重复性的特定场景进行的,我们建议使用基于案例的推理方法,该方法基于计算正在进行的攻击的信息结构与已知目标、工具和方法的混合攻击的回顾性序列的动态相似性。回顾性数据存储在病例库中。该框架结合了几种模型和方法,主要有混合攻击表示的多树模型、混合攻击分布的空间分布模型和混合风险分析方法。混合风险分析方法是在针对每一类风险对象开发的脆弱性模型和后果评估模型两个附加模型的基础上进行的。建议的混合风险分析框架可以在敌方行动发生之前更好地理解它们,并有助于制定对不断变化的情况的适当反应。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
A Framework for Hybrid Risk Analysis
Changes within the worldwide security environment proceed to challenge our ability to comprehend and react to the constantly changing hybrid threats that are becoming more diverse, emanating from a wide range of actors who are enabled by technology. Actors can wield an array of means and ways to further their security interests at the expense of a target and are able to do so without being identified.Developing proper situational awareness is a first and crucial step on the road to achieving better protection against hybrid threats. Here we propose a novel framework for hybrid risk analysis that enables the better understanding of operations of the adversary before their taking place.The idea of the framework is based on the model of hybrid operations, which combine the elements of space, time, objects at risk, goals, and actors into a single structure - a hyper-forest of multi-trees.Taking into account that hybrid operations are carried out according to certain scenarios characterized by repeatability of tools in relation to certain goals, we propose using case-based reasoning approach based on calculating the dynamic similarity of the information structure of ongoing attack to retrospective sequences of hybrid attacks for which the goals, tools, and methods are known. Retrospective data is stored in the case base.The proposed framework combines several models and methods, the main of which are the multi-tree model of hybrid attack representation, spatially distributed model of hybrid attack distribution, and the method for hybrid risk analysis. The method for hybrid risk analysis is based on two additional models such as vulnerability model and consequences assessment model that are developed for each type of object at risk.The suggested framework for hybrid risk analysis offers a better comprehension of adversary operations prior to them occurring and aids in formulating an appropriate reaction to the changing scenario.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信