The Experts below are selected from a list of 11037 Experts worldwide ranked by ideXlab platform

Cleotilde Gonzalez - One of the best experts on this subject based on the ideXlab platform.

  • Cyber Situation Awareness: Modeling the Security Analyst in a Cyber-Attack Scenario through Instance-Based Learning
    2017
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    In a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model.

  • DBSec - Cyber situation awareness: modeling the security analyst in a cyber-Attack Scenario through instance-based learning
    Lecture Notes in Computer Science, 2011
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    Part 9: Short PapersInternational audienceIn a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model

Varun Dutt - One of the best experts on this subject based on the ideXlab platform.

  • Cyber Situation Awareness: Modeling the Security Analyst in a Cyber-Attack Scenario through Instance-Based Learning
    2017
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    In a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model.

  • Cyber Situation Awareness through Instance-Based Learning: Modeling the Security Analyst in a Cyber-Attack Scenario
    Situational Awareness in Computer Network Defense, 2012
    Co-Authors: Varun Dutt, Gleotilde Gonzalez
    Abstract:

    In a corporate network, the situation awareness (SA) of a security analyst is of particular interest. The current work describes a cognitive Instance-Based Learning (IBL) model of an analyst’s recognition and comprehension processes in a cyber-Attack Scenario. The IBL model first recognizes network events based upon events’ situation attributes and their similarity to past experiences (instances) stored in the model’s memory. Then, the model comprehends a sequence of observed events as being a cyber-Attack or not, based upon instances retrieved from its memory, similarity mechanism used, and the model’s risk-tolerance. The execution of the model generates predictions about the recognition and comprehension processes of an analyst in a cyber-Attack. A security analyst’s decisions in the model are evaluated based upon two cyber-SA metrics of accuracy and timeliness. The chapter highlights the potential of this research for design of training and decision support tools for security analysts.

  • DBSec - Cyber situation awareness: modeling the security analyst in a cyber-Attack Scenario through instance-based learning
    Lecture Notes in Computer Science, 2011
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    Part 9: Short PapersInternational audienceIn a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model

Ryo Kurachi - One of the best experts on this subject based on the ideXlab platform.

  • a simultaneous Attack Scenario generation method using the parallel behavior model
    Vehicular Technology Conference, 2020
    Co-Authors: Toshiyuki Fujikura, Ryo Kurachi
    Abstract:

    To achieve high traceability from requirements to test Scenarios, a test Scenario generation method has been widely recognized as being an integral aspect of model-based development. However, it is difficult to make effective test Scenarios that have sufficient requirement coverage including hazardous conditions. In this study, we propose a test Scenario generation method from formalized functional requirements. Based on results from a hazard analysis, this technique is able to generate the Scenario that reveals hazardous situations by specifying a hazardous state as the end-state of a Scenario. Furthermore, by modeling Attack targets and methods, test Scenarios leading to a hazardous state by malicious simultaneous external Attacks are generated. A parallelization technique for generating simultaneous Attack test Scenarios is shown. Using the exhaustive path-finding approach, our results show the ability to achieve high requirement coverage compared to the existing approaches. The proposed method uses a model checking method and cannot escape from the state explosion. However, it is able to reach real problems by modeling the highly-abstract requirement areas and specifying partial Scenarios.

  • an Attack Scenario generation method using the behavior model
    Pacific Rim International Symposium on Dependable Computing, 2019
    Co-Authors: Toshiyuki Fujikura, Ryo Kurachi
    Abstract:

    To achieve high traceability from requirements to test Scenarios, a test Scenario generation method has been widely recognized as being an integral aspect of model-based development. In this study, we propose a test Scenario generation method from formalized functional requirements which employs the approach with the "fluent" proposition. Based on results from a hazard analysis, this technique is able to generate test Scenarios that reveals hazardous situations by specifying a hazardous state as their end-state of a Scenario. Furthermore, by modeling Attack targets and methods, test Scenarios leading to a hazardous state by malicious external Attacks are generated.

Young-suk Ahn - One of the best experts on this subject based on the ideXlab platform.

  • Cyber Situation Awareness: Modeling the Security Analyst in a Cyber-Attack Scenario through Instance-Based Learning
    2017
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    In a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model.

  • DBSec - Cyber situation awareness: modeling the security analyst in a cyber-Attack Scenario through instance-based learning
    Lecture Notes in Computer Science, 2011
    Co-Authors: Varun Dutt, Young-suk Ahn, Cleotilde Gonzalez
    Abstract:

    Part 9: Short PapersInternational audienceIn a corporate network, the situation awareness (SA) of a security analyst is of particular interest. A security analyst is in charge of observing the online operations of a corporate network (e.g., an online retail company with an external webserver and an internal fileserver) from threats of random or organized cyber-Attacks. The current work describes a cognitive Instance-based Learning (IBL) model of the recognition and comprehension processes of a security analyst in a simple cyber-Attack Scenario. The IBL model first recognizes cyber-events (e.g., execution of a file on a server) in the network based upon events’ situation attributes and the similarity of events’ attributes to past experiences (instances) stored in analyst’s memory. Then, the model reasons about a sequence of observed events being a cyber-Attack or not, based upon instances retrieved from memory and the risk-tolerance of a simulated analyst. The execution of the IBL model generates predictions of the recognition and comprehension processes of security analyst in a cyber-Attack. An analyst’s decisions are evaluated in the model based upon two cyber SA metrics of accuracy and timeliness of analyst’s decision actions. Future work in this area will focus on collecting human data to validate the predictions made by the model

Syngyup Ohn - One of the best experts on this subject based on the ideXlab platform.

  • AIS - Automated cyber-Attack Scenario generation using the symbolic simulation
    Lecture Notes in Computer Science, 2005
    Co-Authors: Jongkeun Lee, Minwoo Lee, Jangse Lee, Sungdo Chi, Syngyup Ohn
    Abstract:

    The major objective of this paper is to propose the automated cyber-Attack Scenario generation methodology based on the symbolic simulation environment. Information Assurance is to assure the reliability and availability of information by preventing from Attack. Cyber-Attack simulation is one of noticeable methods for analyzing vulnerabilities in the information assurance field, which requires variety of Attack Scenarios. To do this, we have adopted the symbolic simulation that has extended a conventional numeric simulation. This study can 1) not only generate conventional cyber-Attack Scenarios but 2) generate cyber-Attack Scenarios still unknown, and 3) be applied to establish the appropriate defense strategies by analyzing generated cyber-Attack. Simulation test performed on sample network system will illustrate our techniques.

  • automated cyber Attack Scenario generation using the symbolic simulation
    Ai & Society, 2004
    Co-Authors: Jongkeun Lee, Minwoo Lee, Jangse Lee, Sungdo Chi, Syngyup Ohn
    Abstract:

    The major objective of this paper is to propose the automated cyber-Attack Scenario generation methodology based on the symbolic simulation environment. Information Assurance is to assure the reliability and availability of information by preventing from Attack. Cyber-Attack simulation is one of noticeable methods for analyzing vulnerabilities in the information assurance field, which requires variety of Attack Scenarios. To do this, we have adopted the symbolic simulation that has extended a conventional numeric simulation. This study can 1) not only generate conventional cyber-Attack Scenarios but 2) generate cyber-Attack Scenarios still unknown, and 3) be applied to establish the appropriate defense strategies by analyzing generated cyber-Attack. Simulation test performed on sample network system will illustrate our techniques.