DEFIA: Evaluate defense effectiveness by fusing behavior information of cyberattacks

Zhen Liu, Changzhen Hu, Chun Shan*, Zheheng Peng

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

1 引用 (Scopus)

摘要

The existing researches point to a lack of studies addressing the quantitative evaluation of the effectiveness of cyber defense. This difficult matter has been plaguing cyber security researchers and managers. This paper provides a quantitative method to evaluate defense effectiveness, called DEFIA. DEFIA records information about attack behavior in a formatted way and evaluates the defense effectiveness based on the utility of attack behaviors. By calculating the probability features of the attack behavior in the attack sample, the physical space structure of the attack behavior information is constructed. In particular, we define the utility calculation principle of attack behaviors and regard it as the benchmark for evaluating defensive capabilities. DEFIA can quantitatively assess the defense effectiveness of defense methods deployed in computer systems. We explain how the method works by simulating some real attack scenarios and based on the information provided by Virustotal to prove that DEFIA is reasonable and feasible.

源语言英语
文章编号119375
期刊Information Sciences
646
DOI
出版状态已出版 - 10月 2023

指纹

探究 'DEFIA: Evaluate defense effectiveness by fusing behavior information of cyberattacks' 的科研主题。它们共同构成独一无二的指纹。

引用此