A Systematic Approach to Estimate the Security Posture of a Cyber Infrastructure: A Technical Report

📅 2025-08-29
📈 Citations: 0
Influential: 0
📄 PDF

career value

208K/year
🤖 AI Summary
Scientific research cyberinfrastructure (CI) faces unique challenges—including high collaboration requirements, component heterogeneity, and the absence of adaptable security assessment frameworks. To address these, we propose a mission-centric security posture assessment method: first, top-down identification of critical assets and unacceptable losses; second, construction of a security knowledge graph integrating system components, dependencies, and threat behaviors; and third, integration with directed attack graphs to quantify multi-hop attack paths from entry points to critical assets—enabling visualization of attacker-defender relationships and identification of security blind spots. Unlike conventional generic standards, our approach is the first to deeply couple mission-driven assessment, knowledge graphs, and attack graphs. It supports risk prioritization and generation of actionable defensive strategies, significantly enhancing the precision and effectiveness of CI security defense.

Technology Category

Application Category

📝 Abstract
Academic and research Cyber Infrastructures (CI) present unique security challenges due to their collaborative nature, heterogeneous components, and the lack of practical, tailored security assessment frameworks. Existing standards can be too generic or complex for CI administrators to apply effectively. This report introduces a systematic, mission-centric approach to estimate and analyze the security posture of a CI. The framework guides administrators through a top-down process: (1) defining unacceptable losses and security missions, (2) identifying associated system hazards and critical assets, and (3) modeling the CI's components and their relationships as a security knowledge graph. The core of this methodology is the construction of directed attack graphs, which systematically map all potential paths an adversary could take from an entry point to a critical asset. By visualizing these attack paths alongside defense mechanisms, the framework provides a clear, comprehensive overview of the system's vulnerabilities and security gaps. This structured approach enables CI operators to proactively assess risks, prioritize mitigation strategies, and make informed, actionable decisions to strengthen the overall security posture of the CI.
Problem

Research questions and friction points this paper is trying to address.

Estimating security posture of collaborative cyber infrastructures
Addressing lack of practical security assessment frameworks
Systematically mapping adversary attack paths to critical assets
Innovation

Methods, ideas, or system contributions that make the work stand out.

Mission-centric framework for security posture estimation
Constructs directed attack graphs mapping adversary paths
Visualizes vulnerabilities alongside defense mechanisms overview
🔎 Similar Papers
No similar papers found.