Abstract
dc:description.abstractThe recurring question within the cybersecurity landscape is---why do systems keep getting successfully attacked? This relative ease of system breaches necessitates a reevaluation of what it means for attacks to be ``hard''. Existing security metrics quantify narrow aspects of attack difficulty but do not give insight into why attacks remain feasible. Diversity is frequently discussed as a strategy to mitigate the risks associated with cybersecurity monoculture. However, determining the optimal level and type of diversity in security presents complex challenges for which we have little basis. We propose a new way of conceptualizing attack difficulty in terms of knowledge reuse. To this end, we present two models---one abstract model inspired by artificial intelligence search and another model, product family algebra, inspired by software components. Using these models we propose three new metrics: knowledge obfuscation (KOSM), defense evolution (DESM), and population fragility. We then analyze the practical implications of our proposed models for an information security analyst. By adopting these models, information security analysts can better navigate the complexities of the cybersecurity landscape, tailor security measures more precisely to their organization's needs, and ultimately contribute to a more resilient and secure digital environment.
Degree
thesis:*- Name thesis:degree_name
- Doctor of Philosophy (Ph.D.)
- Level thesis:degree_level
- Doctoral
- Discipline thesis:degree_discipline
- Computer Science
- Grantor dc:publisher
- Carleton University
- Year dc:date.issued
- 2024
Author and committee
dc:creator, dc:contributor.*- Author dc:creator
-
- Mansourzadeh, Nilofar
Rights
dc:rights- Statement dc:rights
-
- Copyright © 2024 the author(s). Theses may be used for non-commercial research, educational, or related academic purposes only. Such uses include personal study, distribution to students, research and scholarship. Theses may only be shared by linking to the Carleton University Institutional Repository and no part may be copied without proper attribution to the author; no part may be used for commercial purposes directly or indirectly via a for-profit platform; no adaptation or derivative works are permitted without consent from the copyright owner.
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- OAI identifier oai:identifier
- oai:carleton.scholaris.ca:20.500.14718/43041