Understanding How Components of Organisations Contribute to Attacks

TitleUnderstanding How Components of Organisations Contribute to Attacks
Publication TypeConference Paper
Year of Publication2016
AuthorsGu M., Aslanyan Z., Probst C.W
Conference Name21st Nordic Conference, NordSec 2016, Oulu, Finland
Date PublishedOctober
PublisherSpringer International Publishing
Conference LocationLondon

Attacks on organisations today explore many different layers, including buildings infrastructure, IT infrastructure, and human factor - the physical, virtual, and social layer. Identifying possible attacks, understanding their impact, and attributing their origin and contributing factors is difficult. Recently, system models have been used for automatically identifying possible attacks on the modelled organisation. The generated attacks consider all three layers, making the contribution of building infrastructure, computer infrastructure, and humans (insiders and outsiders) explicit. However, this contribution is only visible in the attack trees as part of the performed steps; it cannot be mapped back to the model directly since the actions usually involve several elements (attacker and targeted actor or asset). Especially for large attack trees, understanding the relations between several model components quickly results in a large quantity of interrelations, which are hard to grasp. In this work we present several approaches for visualising attributes of attacks such as likelihood of success, impact, and required time or skill level. The resulting visualisations provide a link between attacks on an organisations and the contribution of parts of an organisation to the attack and its impact.