John Homer Promotion Portfolio

August 14, 2018

Abstract: Risk Analysis with Execution-based Model Generation

Filed under: — John Homer @ 9:58 am

Analyzing risk is critical throughout the software acquisition lifecycle. System risk is assessed by conducting a penetration test, where ethical hackers portray realistic threat on real systems by exploiting vulnerabilities. These tests are very costly, limited in duration, and do not provide stakeholders with “what-if” analyses. To alleviate these issues, system models are used in emulation, simulation, and attack graph generators to enhance test preparation, execution, and supplementary post-test analyses.

This article describes a method for developing models that can be used to analyze risk in mixed tactical and strategic networks, which are common in the military domain.

No Comments

No comments yet.

RSS feed for comments on this post.

Sorry, the comment form is closed at this time.

Powered by WordPress