Author:
Zacharis Alexandros,Katos Vasilios,Patsakis Constantinos
Abstract
AbstractThe escalating complexity and impact of cyber threats require organisations to rehearse responses to cyber-attacks by routinely conducting cyber security exercises. However, the effectiveness of these exercises is limited by the exercise planners’ ability to replicate real-world scenarios in a timely manner that is, most importantly, tailored to the training audience and sector impacted. To address this issue, we propose the integration of AI-driven sectorial threat intelligence and forecasting to identify emerging and relevant threats and anticipate their impact in different industries. By incorporating such automated analysis and forecasting into the design of cyber security exercises, organisations can simulate real-world scenarios more accurately and assess their ability to respond to emerging threats. Fundamentally, our approach enhances the effectiveness of cyber security exercises by tailoring the scenarios to reflect the threats that are more relevant and imminent to the sector of the targeted organisation, thereby enhancing its preparedness for cyber attacks. To assess the efficacy of our forecasting methodology, we conducted a survey with domain experts and report their feedback and evaluation of the proposed methodology.
Publisher
Springer Science and Business Media LLC
Reference67 articles.
1. Acarturk, C., Sirlanci, M., Balikcioglu, P.G., Demirci, D., Sahin, N., Kucuk, O.A.: Malicious code detection: run trace output analysis by lstm. IEEE Access 9, 9625–9635 (2021)
2. Almahmoud, Z., Yoo, P.D., Alhussein, O., Farhat, I., Damiani, E.: A holistic and proactive approach to forecasting cyber threats. Sci. Rep. 13(1), 8049 (2023)
3. ANSII: Organising a cyber crisis management exercise (2021). https://www.ssi.gouv.fr/guide/organising-a-cyber-crisis-management-exercise/
4. Armstrong, J.S., Collopy, F.: Error measures for generalizing about forecasting methods: empirical comparisons. Int. J. Forecast. 8(1), 69–80 (1992)
5. Augustine, T., Dodge, R.C., et al.: Cyber defense exercise: meeting learning objectives thru competition. In: Proceedings of the 10th Colloquium for Information Systems Security Education (2006)
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献