애스크로AIPublic Preview
← 학술논문 검색
학술논문인터넷정보학회논문지2025.06 발행

Cybersecurity Risk Assessment: An Asset-Based Approach to Pre-Attack Threat Analysis

Cybersecurity Risk Assessment: An Asset-Based Approach to Pre-Attack Threat Analysis

이현민(Risk Managment Lab, Korea University, Korea); 이경호(고려대학교)

26권 3호, 19~33쪽

초록

With the arrival of the digital era and the increasing importance of information technology, governments and enterprises alike have been targets of developing cyberattack campaigns performed by advanced persistent threat groups. In an effort to identify these cyber threat actors, the concept of threats, techniques, and protocols has been introduced by security professionals. Frameworks that compile TTPs such as MITRE ATT&CK are now commonly used in order to not only identify an advanced persistent threat group, but also to respond accordingly in the case of an attack. However, it is widely known that predicting assets at risk before an attack occurs is a challenging task given the attacker’s advantage. To mitigate this advantage, preparation for cyberattacks requires thorough analysis before an incident has occurred. This research aims to introduce a means to model and quantify risk by introducing with a focus on TTPs and attack trees for prioritization of assets in a timely manner. Furthermore, this methodology is applied to a real-world scenario to analyze the strengths and shortcomings.

Abstract

With the arrival of the digital era and the increasing importance of information technology, governments and enterprises alike have been targets of developing cyberattack campaigns performed by advanced persistent threat groups. In an effort to identify these cyber threat actors, the concept of threats, techniques, and protocols has been introduced by security professionals. Frameworks that compile TTPs such as MITRE ATT&CK are now commonly used in order to not only identify an advanced persistent threat group, but also to respond accordingly in the case of an attack. However, it is widely known that predicting assets at risk before an attack occurs is a challenging task given the attacker’s advantage. To mitigate this advantage, preparation for cyberattacks requires thorough analysis before an incident has occurred. This research aims to introduce a means to model and quantify risk by introducing with a focus on TTPs and attack trees for prioritization of assets in a timely manner. Furthermore, this methodology is applied to a real-world scenario to analyze the strengths and shortcomings.

발행기관:
한국인터넷정보학회
분류:
컴퓨터학

AI 법률 상담

이 논문의 주제에 대해 더 알고 싶으신가요?

460만+ 법률 자료에서 관련 판례·법령·해석례를 찾아 답변합니다

AI 상담 시작
Cybersecurity Risk Assessment: An Asset-Based Approach to Pre-Attack Threat Analysis | 인터넷정보학회논문지 2025 | AskLaw | 애스크로 AI