Low-impact, near real-time risk assessment for legacy IT infrastructures


연구 분야: Infrastructure



학회: International Journal of Information Security


초록

In an era where cybersecurity threats are evolving at an unprecedented pace, this paper introduces a methodology for near real-time risk assessment of high-profile, high security infrastructures, where data security and operational continuity inherently limits observability. Our approach addresses the challenges of this limited observability and minimized disruption, offering a new perspective on processing and evaluating cybersecurity knowledge. We present an innovative method that leverages attack graphs and attacker behavior analysis to assess risks and vulnerabilities. Our research includes the development of an automated risk assessment mechanism, graphical security modeling, and a Markov chain-based model for attacker behavior. Our methodology utilizes a blend of direct and indirect event sources, incorporating an attacker behavioral model based on a random walk method akin to Google’s PageRank. The proof-of-concept solution calculates potential risk according to the actual threat landscape, providing a more accurate and timely assessment.


Author Profile
Eszter Kail

John von Neumann Faculty of Informatics Óbuda University Bécsi út 96/B Budapest 1034 Hungary

Hungary
Author Profile
Annamária Riethné Nagy

HUN-REN Institute for Computer Science and Control Kende u. 13-17 Budapest 1111 Hungary

Andorra
Author Profile
Rita Fleiner

HUN-REN Institute for Computer Science and Control Kende u. 13-17 Budapest 1111 Hungary

Andorra

📄 논문 정보

발행 연도 2025년
인용수 0
출판 국가 Hungary, Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (190건)