YaBeSH Engineering and Technology Library

    • Journals
    • PaperQuest
    • YSE Standards
    • YaBeSH
    • Login
    View Item 
    •   YE&T Library
    • ASCE
    • Journal of Infrastructure Systems
    • View Item
    •   YE&T Library
    • ASCE
    • Journal of Infrastructure Systems
    • View Item
    • All Fields
    • Source Title
    • Year
    • Publisher
    • Title
    • Subject
    • Author
    • DOI
    • ISBN
    Advanced Search
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    Archive

    Protecting Critical Infrastructure for Disasters: NLP-Based Automated Information Retrieval to Generate Hypothetical Cyberattack Scenarios

    Source: Journal of Infrastructure Systems:;2024:;Volume ( 030 ):;issue: 003::page 04024008-1
    Author:
    Christin Salley
    ,
    Neda Mohammadi
    ,
    John E. Taylor
    DOI: 10.1061/JITSE4.ISENG-2407
    Publisher: American Society of Civil Engineers
    Abstract: Cyberattacks disrupt systems, leaving critical infrastructure vulnerable to adversaries, especially during natural disasters. Furthermore, when both a cyberattack and a natural disaster occur concurrently, there are limited tools to ensure further damage beyond the physical is not experienced in crucial societal systems, such as emergency services, which need to operate during any type of hazard. Two prominent knowledge bases for adversary attacks in the cybersecurity community are the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) Enterprise Matrix and the National Institute of Standards and Technology (NIST) Cybersecurity Framework. Existing processes to derive possible attack methodologies in general from such sources are largely manual and time-consuming. It is essential to automate the information retrieval process to improve efficiency and free up resources for identifying potential cyberattacks. It is also important to identify preventive measures with both human-made and natural hazards in mind. We propose an approach that incorporates Natural Language Processing (NLP) to automatically generate sets of attack paths from the technique descriptions in the Matrix, with both cyber-based and emergency management–based contexts, then map these techniques to the Framework to identify potential relationships between techniques and outlined protective actions. The approach generates outputs showing potential pathways an adversary can take to infiltrate a system, and its respective defense action based on similarity measures. The similarities between techniques and the Framework are evaluated with p-values to determine relevancy of pairings. The results of this study provide an approach to more quickly and effectively assess potential cyberattacks toward protecting critical infrastructure that can be utilized in broader vulnerability analyses, considering contextual data to represent both cyber and natural disaster events.
    • Download: (784.9Kb)
    • Show Full MetaData Hide Full MetaData
    • Get RIS
    • Item Order
    • Go To Publisher
    • Price: 5000 Rial
    • Statistics

      Protecting Critical Infrastructure for Disasters: NLP-Based Automated Information Retrieval to Generate Hypothetical Cyberattack Scenarios

    URI
    http://yetl.yabesh.ir/yetl1/handle/yetl/4299103
    Collections
    • Journal of Infrastructure Systems

    Show full item record

    contributor authorChristin Salley
    contributor authorNeda Mohammadi
    contributor authorJohn E. Taylor
    date accessioned2024-12-24T10:32:10Z
    date available2024-12-24T10:32:10Z
    date copyright9/1/2024 12:00:00 AM
    date issued2024
    identifier otherJITSE4.ISENG-2407.pdf
    identifier urihttp://yetl.yabesh.ir/yetl1/handle/yetl/4299103
    description abstractCyberattacks disrupt systems, leaving critical infrastructure vulnerable to adversaries, especially during natural disasters. Furthermore, when both a cyberattack and a natural disaster occur concurrently, there are limited tools to ensure further damage beyond the physical is not experienced in crucial societal systems, such as emergency services, which need to operate during any type of hazard. Two prominent knowledge bases for adversary attacks in the cybersecurity community are the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) Enterprise Matrix and the National Institute of Standards and Technology (NIST) Cybersecurity Framework. Existing processes to derive possible attack methodologies in general from such sources are largely manual and time-consuming. It is essential to automate the information retrieval process to improve efficiency and free up resources for identifying potential cyberattacks. It is also important to identify preventive measures with both human-made and natural hazards in mind. We propose an approach that incorporates Natural Language Processing (NLP) to automatically generate sets of attack paths from the technique descriptions in the Matrix, with both cyber-based and emergency management–based contexts, then map these techniques to the Framework to identify potential relationships between techniques and outlined protective actions. The approach generates outputs showing potential pathways an adversary can take to infiltrate a system, and its respective defense action based on similarity measures. The similarities between techniques and the Framework are evaluated with p-values to determine relevancy of pairings. The results of this study provide an approach to more quickly and effectively assess potential cyberattacks toward protecting critical infrastructure that can be utilized in broader vulnerability analyses, considering contextual data to represent both cyber and natural disaster events.
    publisherAmerican Society of Civil Engineers
    titleProtecting Critical Infrastructure for Disasters: NLP-Based Automated Information Retrieval to Generate Hypothetical Cyberattack Scenarios
    typeJournal Article
    journal volume30
    journal issue3
    journal titleJournal of Infrastructure Systems
    identifier doi10.1061/JITSE4.ISENG-2407
    journal fristpage04024008-1
    journal lastpage04024008-12
    page12
    treeJournal of Infrastructure Systems:;2024:;Volume ( 030 ):;issue: 003
    contenttypeFulltext
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian
     
    DSpace software copyright © 2002-2015  DuraSpace
    نرم افزار کتابخانه دیجیتال "دی اسپیس" فارسی شده توسط یابش برای کتابخانه های ایرانی | تماس با یابش
    yabeshDSpacePersian