Incorporating the human element in anticipatory and dynamic cyber defense

Aunshul Rege · 2016

Advanced Persistent Threats (APTs) use sophisticated cyberattacks to disrupt a nation's critical infrastructure. Conventional cyberattack management is response-driven, which (while important) is ineffective, especially in managing APTs. There is an immediate need for anticipatory defense measures that reflect the adaptive nature of this new breed of adversaries. This paper identifies five main research areas that need immediate attention. Using a criminological framework and empirical evidence of observations and interviews done at Industrial Control Systems Computer Emergency Response Team's (ICS-CERT) Red/Blue cybersecurity training exercise held at Idaho National Laboratory, this paper argues that understanding how adversaries adapt at various points in the intrusion chain is crucial in profiling APTs and developing anticipatory cybersecurity measures. The paper offers recommendations for further research and the relevance of multidisciplinary collaboration.

Read the paper · More papers on PaperTik