Gateway to Think Tanks
来源类型 | Report |
规范类型 | 报告 |
DOI | https://doi.org/10.7249/RR-A382-1 |
来源ID | RR-A382-1 |
RAND's Scalable Warning and Resilience Model (SWARM): Enhancing Defenders' Predictive Power in Cyberspace | |
Bilyana Lilly; Adam S. Moore; Quentin E. Hodgson; Daniel Weishoff | |
发表日期 | 2021-05-11 |
出版年 | 2021 |
语种 | 英语 |
结论 | The variety of cyber threats that organizations face necessitates a tailored and targeted approach to cyber security
SWARM is a four-step threat-centric process that facilitates the prioritization of threats while enhancing resilience and predictive power
|
摘要 | In the first two decades of the 21st century, the coevolutionary adaptation of cyber threat actors and technology has been akin to an escalatory arms race between cyber offense and cyber defense. Paradigm-shifting technology advancement, transparent unclassified reporting on cyber incidents, and the proliferation of open-source hacking tools in the context of complex geopolitical dynamics further exacerbate the cyber defense challenge. Although the integration of such practices as cyber threat modeling, information-sharing, and threat-hunting into defensive strategies has become more common in recent years, the cyber defense community needs to continue to push the envelope to become more resilient and, ideally, get ahead of the threats facing organizations. ,This research endeavors to contribute to the community via the formulation of a process-based model called the Scalable Warning and Resilience Model (SWARM), which focuses on cyber threats from state-sponsored actors but without the assumption of access to classified information or assets. SWARM prioritizes threat detection, facilitates better prediction of cyber incidents, and enhances network resilience by combining processes that seek to help organizations anticipate and defend against attackers. The model tailors data collection, cyber threat intelligence, and penetration testing to the particular type of intrusion sets most likely to target one's network. ,This proposed model adapts the concept of applying both resilience and indications and warning (I&W) frameworks to information environments while also incorporating a combination of tailored threat modeling and emulation. This report also includes a case study—based on cyber incidents that occurred at the RAND Corporation—that demonstrates how the model has the potential to produce promising results for defenders by proactively protecting their systems through early warning of cyber incidents before they occur. |
目录 |
|
主题 | Cyber Warfare ; Data Analysis ; Information Operations ; Intelligence Collection ; Modeling and Simulation ; North Korea ; Threat Assessment |
URL | https://www.rand.org/pubs/research_reports/RRA382-1.html |
来源智库 | RAND Corporation (United States) |
引用统计 | |
资源类型 | 智库出版物 |
条目标识符 | http://119.78.100.153/handle/2XGU8XDN/524448 |
推荐引用方式 GB/T 7714 | Bilyana Lilly,Adam S. Moore,Quentin E. Hodgson,et al. RAND's Scalable Warning and Resilience Model (SWARM): Enhancing Defenders' Predictive Power in Cyberspace. 2021. |
条目包含的文件 | ||||||
文件名称/大小 | 资源类型 | 版本类型 | 开放类型 | 使用许可 | ||
RAND_RRA382-1.pdf(6212KB) | 智库出版物 | 限制开放 | CC BY-NC-SA | 浏览 | ||
x1620736692576.jpg.p(2KB) | 智库出版物 | 限制开放 | CC BY-NC-SA | 浏览 |
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。