Development of a holistic method for cyber attack classification
Project Idea Metadata
- Project Idea Name: Development of a holistic method for cyber attack classification
- Date: 11/22/2021 8:00:34 AM
- Administrators:
Project Idea Description
Companies are increasingly targeted by attacks of criminal and state-sponsored organizations. The methods of the attacks vary depending on the target group, published vulnerabilities, time period, and attacker. Companies could benefit from support in the area of attack methods when assessing the risk for their own company. To the author's knowledge, there is no clear classification methodology for known or novel attack methods, and its rating would vary by company.
If the attackers exploit new vulnerabilities as part of a new attack method, existing vulnerability classifications such as the Common Vulnerability Scoring System are inadequately aligned with the company's circumstances, importance of business areas or, for example, the company's field of activity.
The objective of this work is to identify or elaborate a complementary methodology to an existing methodology for the holistic classification of attack methods on enterprises in order to provide a better, more advanced risk assessment for enterprise environments. The methodology shall have individualizing elements to enable classification of an attack for an enterprise. The methodology shall also support in determining new attack methods.
The methodology shall be tested on a previous attack that has been firstly described in a theoretical research paper.
Procedure:
Literature research on the classification of attack methods, theoretical research on new attack methods, vulnerability management and risk management, as well as existing standards or reference frameworks that are helpful for this thesis.
The procedure model of the bachelor thesis is a combination of the waterfall model for literature and fundamental research, and an iterative process model for the identification, development, application and improvement of the methodology.
The objective of this work is to identify or elaborate a complementary methodology to an existing methodology for the holistic classification of attack methods on enterprises in order to provide a better, extended risk assessment for enterprise environments.
The methodology shall be tested on a previous attack that has been firstly described in a theoretical research paper.