<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Using a Semantic Approach to Cyber Impact Assessment</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexandre de Barros Barreto</string-name>
          <email>kabart@ita.br</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Edgar Toshiro Yano</string-name>
          <email>yano@ita.br</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Instituto Tecnolo ́gico de Aerona ́utica</institution>
          ,
          <addr-line>Sa ̃o Jose ́ dos Campos SP</addr-line>
          <country country="BR">Brasil</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Instituto Tecnolo ́gico de Aerona ́utica</institution>
          ,
          <addr-line>Sa ̃o Jose ́ dos Campos SP</addr-line>
          <country country="BR">Brasil</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2013</year>
      </pub-date>
      <abstract>
        <p>-The use of cyberspace as a platform for military operations presents many new research challenges. This paper focuses on the specific problem of assessing the impact of an event in the cyber domain (e.g. a cyber attack) on the missions it supports. The approach involves the use of Cyber-ARGUS, a C2 simulation framework, along with semantic technologies to provide consistent mapping between domains. Relevant information is stored in a semantic knowledge base about the nodes in the cyber domain, and then used to build a Bayesian network to provide impact assessment. The technique is illustrated through the simulation of an air transportation scenario in which the C2 infrastructure is subjected to various cyber attacks, and their associated impact to the operations is assessed. Index Terms-Impact assessment, cyber-security, Bayesian Networks, C2, semantic technologies.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>I. INTRODUCTION</p>
      <p>With the increasing automation of processes and systems
that are part of critical infrastructures supporting military and
civilian operations, the cyber domain became one of most
crucial aspects in strategic planning.</p>
      <p>
        As a result, major military players in the world stage started
to envision cyberspace as a medium to extend their
capabilities, in addition to their existing competencies in the traditional
domains (land, air and sea) [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. However, understanding how
cyber operations affect operations and leveraging their effects
on the mission are no trivial tasks [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ].
      </p>
      <p>To understand the significance of a cyber event in a mission
requires mapping physical tasks to their required
infrastructure, in a way of creating an integrated view of cyber and
physical behaviors. The inherent complexity of this
requirement implies, among other things, that an experienced mission
analyst must be able to access all relevant data pertaining to
the infrastructure and translate it to the support team. Further,
this must be done in a way that allows them to understand the
real impact of cyber threats not only on the network, but also
on the mission it supports.</p>
      <p>Many approaches exist to assess cyber impact. However,
most are not suitable for supporting complex cyber impact
assessment in real situations, where the correlation between
kinetic tasks and cyber events needs to be assessed continuously,
and with a high temporal resolution. This is a considerable gap
that has not been successfully filled, in spite of the relatively
large body of research focused on the subject.</p>
      <p>This paper presents the Cyber-ARGUS Framework, which
leverages semantic technologies to fuse data collected from
sensors within the physical and the cyber domains, as well
as to retrieve information relevant to the assessment of cyber
impact.</p>
      <p>The main contribution of Cyber-ARGUS is to provide a
mapping of how cyber-events impact tasks in operational level
as the mission unfolds. The framework does not create
complete maps of vulnerabilities and attacks, or a comprehensive
view of how these vulnerabilities and attacks can affect the
overall mission. Instead, the framework is meant to provide
analysts who need real-time decision support with a
simplified situational awareness, which includes understanding what
assets are more critical in accomplishing the most important
tasks and how these assets are impacted during a cyber attack.
As an example from the case study developed for this research,
consider the problem of an Air Traffic Security Analyst,
who needs to define which elements need to be prioritized
to ensure mission success. This analyst must consider data
from a large set of different sensors and components, and
perform his analysis within very tight time constraints. In his
situation, a complete understanding of the current attacks and
fault-trees is neither feasible nor necessary, and his task can
be accomplished with the simplified mapping and associated
impact analysis provided by Cyber-ARGUS.</p>
      <p>
        This paper extends previous work from [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ] by addressing
how Cyber-ARGUS evaluates the cyber impact on the mission.
Among other additions, this paper provides a more detailed
explanation on how data from sensors is aggregated, how
node-statuses are calculated, and how impact is propagated
throughout the network.
      </p>
      <p>To evaluate the Cyber-ARGUS capabilities, we have
independently designed a specific air traffic service (ATS) scenario
that relies on a new protocol to perform air traffic control
in a critical area located at the Campos basin, Brazil. The
scenario provides a rich environment to understand how such
capabilities can be employed in real life critical operation. The
basin, located in the littoral of the Rio de Janeiro state, is a
petroleum rich area responsible for 80% of Brazil’s petroleum
production. ATS missions are critical, happen in real time, and
attacks can result not only in considerable economic loss but
also in risk of human lives.</p>
      <p>This paper is organized as follows. Section II describes the
main concepts of the framework being proposed, as well as a
brief survey of the most relevant approaches developed so far
to address the problem. Section III conveys a short summary
of the Cyber-ARGUS framework, discussing its core ideas.
Section IV explains in detail the impact assessment process.
Section V presents the study case developed independently for
this research, showing the application of Cyber-ARGUS in a
specific situation. Section VI presents the results and provides
a brief analysis of their significance. Finally, Section VII
brings a few considerations and raises issues that must be
addressed in future research.</p>
      <p>II. BACKGROUND AND RELATED RESEARCH</p>
      <p>
        As implied above, understanding how cyber events affect
the missions happening outside the cyber domain is a major
requirement for military operations. A common approach for
detecting intrusions and system attacks is to use a set of
distributed sensors in the network. Preliminary work on this
subject focused on specialist or signature-based systems [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ],
[
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
      </p>
      <p>However, understanding the significance of a cyber-event to
a supported mission requires more than identifying attacks and
suspect events. It is also necessary to assess their impact on
the mission.</p>
      <p>
        Cyber Impact Assessment can be understood as the
estimation and prediction of effects on planned or estimated/predicted
actions by participants; including interactions between action
plans of several players (e.g. Assessing susceptibilities and
vulnerabilities to estimated/predicted threat actions given one’s
own planned actions) [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        Most approaches attempt to predict how vulnerabilities can
be exploited by the enemy (enemy’s focus) [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Usually,
an attack graph [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ] that includes vulnerabilities and exploit
strategies is generated. Then, an analyst leverages information
contained in the graph to calculate impact assessment.
      </p>
      <p>
        There are a number of issues with this approach. As an
example, there are situations in which it is not possible to
predict the enemy’s behavior, due to the lack of evidence
(e.g. on attacks or its detection) resulting in ignorance of
selfvulnerabilities or of enemy capabilities. Another issue is the
computational problem involved in creating and evaluating the
graphs [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>
        A recent approach is based on the belief that it is not
necessary to identify the enemy’s plan or to recognize its
actions against one’s system. Instead, it is only necessary
to know the impact that any plan (ours and enemy’s) can
have on one’s system (mission) [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. In other words, it is
easier to understand the enemy’s capabilities and restrictions
than it is to predict his behavior. This approach focuses on
effects; and does not require one to detect attacks or attackers,
but to understand the spectrum of potential effects on the
mission. To measure the impact, a model of the mission must
be built that includes all critical components that must be
identified and monitored. However, [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]–[
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] do not describe
how to accomplish the mapping between cyber and non-cyber
components in detail, as well how to assess the impact of cyber
events using real infrastructure data.
      </p>
      <p>
        An approach to cyber impact assessment was proposed by
Holsopple et al. [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. They define a normalized compromising
score, which represents the level of compromise that a node
has caused by a specific threat. This method requires defining
the threat severity level. One potential approach is to use the
Common Vulnerability Scoring System (CVSS). CVSS is a
free and open industry standard for assessing the severity of
computer system security vulnerabilities.
      </p>
      <p>
        Even if an analyst knows which attributes are critical to the
mission; a second question needs to be answered: how to
combine these attributes and generate an index to support coherent
and consistent decisions? One strategy is to employ
multicriteria decision making methods (MCDM), a sub-discipline of
operations research that explicitly considers multiple criteria
in decision-making environments. MCDM provides a set of
different approaches that can potentially be used in this
cyberimpact assessment. One example is provided in [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ], which
uses the Technique for Order Preference by Similarity to Ideal
Solution (TOPSIS) for threat assessment. TOPSIS is a
multicriteria decision analysis method based on the concept that the
chosen alternative should have the shortest geometric distance
from the positive ideal solution, and the longest geometric
distance from the negative ideal solution [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ].
      </p>
      <p>
        Another applicable technique from the MCDM toolbox
is presented by [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], which combines Analytic Hierarchy
Process (AHP) and TOPSIS for quantifying the degree of
security. AHP can be seen as a weight elicitation method
based on pairwise comparisons between attributes, and can
thus be employed to produce a consistent multi-attribute value
structure from experts’ input.
      </p>
      <p>
        Kim and Kang [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ] present another MCDM technique to
evaluate the critical assets needed to accomplish a mission.
Their approach is extremely attractive because it allows for
calculating the asset value during a mission using local and
global classification. Since the approach involves working in
a real-time environment, the authors modified the TOPSIS
process to calculate the worst (A-) alternative and the best
alternative (A+). Also, a set of maximum and minimum
acceptable levels is defined as a means to ensure acceptable
performance.
      </p>
      <p>
        However, this approach has two interrelated limitations.
Initially, it was not designed to handle tasks, which are key
aspects in defining time sensitive aspects of the mission. As a
result of this limitation, the technique becomes less suitable for
evaluating distinct phases of a mission. For example, during
deployment of a laser-guided bomb by an aircraft, both the
soldier illuminating the target (e.g. from a nearby location) as
well as the aircraft launching the bomb play equally critical
tasks. However, after the ordnance release the aircraft loses
its relative importance, since the bomb now relies only on the
soldier’s laser device in its flight to the target. Such
timesensitive situations cannot be modeled using the approach
stated in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        In addition to the impact assessment calculations, a key
aspect is to propagate the impact assessed locally in a way
of ensuring a coherent understanding of its consequences
from a global perspective. A Markov approach approach to
model security risk was developed by [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ]. However, using
Markov processes to propagate impact assessment brings
the weakness of the technique’s inability to represent
nonmonotonic dependencies. For instance, in this technique two
independent variables must be directly connected by an edge,
merely because there are some other variable that depends on
both [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
      </p>
      <p>
        An alternative for modeling risk propagation is Bayesian
Networks (BN). Examples of its use for solving real impact
assessment problems can be found in [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ], [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. Li et al. [
        <xref ref-type="bibr" rid="ref21">21</xref>
        ]
combine CVSS and Attack Graphs in a consistent
representation using BNs - which are used to represent the uncertain
aspects between exploitation attack paths and the required
vulnerabilities. However, we were not able to find a formal
description on how to build and elicit the probability tables,
which is essential for implementing the technique in a real
situation.
      </p>
      <p>
        Similar the aforementioned work, Singhal and Ou [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ] show
how to propagate the risk, which is calculated using CVSS
metrics, through an enterprise environment using probabilistic
attack graph. The latter can be understood as an attack graph
that has the associated uncertainty handled by BNs. One
problem that is common to all the aforementioned approaches
that use BNs to represent uncertainty in attack graphs is that
they require complete knowledge of the enemy, a precondition
that renders these modeling techniques unrealistic for practical
problems.
      </p>
      <p>
        A different use of BNs is presented by Duan and Babu
[
        <xref ref-type="bibr" rid="ref23">23</xref>
        ], which periodically collects performance data at three
levels: applications, database server, and operating system. The
collected data is used to construct probabilistic models for
predicting service-level violations. This approach is extremely
similar to that of [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ], where the impact is calculated
by identifying the critical components of mission, their
dependences, as well as the effects of their respective failure,
and then using a BN to propagate the beliefs to the overall
mission.
      </p>
      <p>III. CYBER-ARGUS FRAMEWORK REVIEW</p>
      <p>
        The goal of this research is to design a framework that
enables the understanding of cyber impact within a mission
context. This chapter introduces the Cyber-ARGUS
framework, which is meant to support this goal. Unlike most
approaches cited in Section II, the framework is based on a
mission viewpoint approach [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. From this perspective,
the focus is on measuring how the effect generated by a
cyberevent intervenes on the results of tasks performed in a mission.
      </p>
      <p>
        Mapping from the cyber domain to the mission domain
requires a few concepts to be defined (e.g. mission, service,
and cyber node). The DoD Architectural Framework [
        <xref ref-type="bibr" rid="ref24">24</xref>
        ]
defines a mission as composed by a task (or set of tasks),
together with its associated purpose that clearly indicates the
action to be taken assigned to an individual or unit. A service
is a mechanism that enables access to a set of one or more
capabilities. In other words, availability of services define
which tasks can be performed. The last concept is cyber node,
which is the element that hosts one or more services.
      </p>
      <p>
        To understand how an event can produce effects in a
mission, Cyber-ARGUS uses an adaptation of the impact
dependence graph presented in [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. The adapted graph includes
all relations between tasks; tasks and services; as well as
between services and cyber nodes, resulting in a structure that
makes it easier to assess the consequences that follow when
a node is compromised. Cyber-ARGUS flow of activities is
comprised of three main phases [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ]: 1) Mission
Modeling, 2) Collection Cyber and Mission Situation Awareness,
and 3) Cyber Impact Assessment. The first two are treated in
parts A and B of this Section, while the latter is explained in
more detail in Section IV.
      </p>
      <p>A. Mission Modeling</p>
      <p>During the first phase, the core idea is to capture all
information about the tasks required to accomplish the mission
and consolidate these in an integrated data representation.
This allows for a comprehensive analysis to be performed.
In our framework, the importance of any given element is
measured with respect to its relevance to impact assessment,
and includes the associated tasks, the relationships between
tasks, objectives, resources required to develop the mission
and, finally, the task performer (i.e., entity or set of entities
that have the responsibility to execute the mission).</p>
      <p>
        Mission information usually comes from diverse sources,
so Cyber-ARGUS ensures consistency of the integrated data
representation by means of a mission ontology describing
the relevant concepts (tasks, services, nodes, etc.). Semantic
technologies also facilitate code reuse, which allow us to avoid
having to develop the mission ontology from scratch. Instead,
Cyber-ARGUS leverages previous related work by D’Amico
et al. [
        <xref ref-type="bibr" rid="ref26">26</xref>
        ] and Matheus et al. [
        <xref ref-type="bibr" rid="ref27">27</xref>
        ] in its own architecture.
      </p>
      <p>
        Within this phase of the Cyber-ARGUS activity flow, a
mission analyst can design the mission model using any business
process language. The goal is to capture the most relevant
information of the mission within the model and store it in a
semantic Knowledge Base (KB). In the current research, we
leveraged previous experience within our group and made the
design decision of capturing these aspects using the Business
Process Modeling Notation (BPMN) [
        <xref ref-type="bibr" rid="ref28">28</xref>
        ]. However, as already
mentioned, any business modeling language with the ability to
capture the information described above could have been used
and, therefore, might be used with the framework in the future.
      </p>
      <p>BPMN was not only convenient as a development tool
for the framework, but also proved to be rather suitable for
capturing the main aspects of a mission. This is especially
true in civilian environments such as air traffic management,
nuclear power plants, and others. Its business-oriented notation
made it easier to accommodate air traffic domain concepts
used in the evaluation part of the research, while also providing
a relatively straightforward mapping to the associated concepts
in the mission ontology.</p>
      <p>The outcome of this first phase includes the mapping of
tasks, sequences, and dependencies between them and the
required services. Yet, there is no information on where these
services are hosted, so the framework queries a service
repository and retrieves all information linking IT nodes to their
respective hosted services, as well as the network topology
depicting the required connectivity.</p>
      <p>Once this is accomplished, the framework has all critical
information about mission (tasks; service dependencies; and
cyber nodes) and can proceed with the next task, vulnerability
discovery. The goal now is to locate all vulnerabilities in
the infrastructure and store it into the KB to be used in
the mission impact assessment phase. This is similar to an
infrastructure discovery process, where the framework, using
a database, looks for node vulnerabilities that are part of the
environment. After this activity, all vulnerabilities and their
related impact factors are collected, and Cyber-ARGUS stores
this information into the KB. The classification is conducted
by nodes, enabling an analyst to perform specific queries
relating nodes to vulnerabilities and vice-versa.</p>
      <p>
        The last activity within the Mission Modeling phase to
model enemy behavior. Here, the goal is to model known
attack-paths using an attack graph. This task requires the
existence of a database in which all known attack-paths are
described and saved in an appropriate format. To reduce the
number of information that Cyber-ARGUS will use during
impact assessment phase, we adopted the Cauldron approach
developed at GMU [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Cauldron uses firewalls and others
entrance devices’ rules to eliminate implausible scenarios.
This strategy reduces the number of nodes and the overall
complexity of the original graph, generating a much simpler
version that is stored into the Cyber-ARGUS KB as well.
B. Collection Cyber and Mission Situation Awareness
      </p>
      <p>After the Mission Modeling phase, the analyst has a
comprehensive view of the mission and the factors that affect
its success. That is, the Cyber-ARGUS model is ready to
be used; it is now able to collect and correlate infrastructure
information, to infer what is pertinent to the mission, and to
provide relevant data to calculate cyber impact.</p>
      <p>To use this model, the mission analyst needs to collect
information from cyber nodes. This will enable him to assess
each node’s current status, as well as to estimate, during the
impact assessment phase, whether the node is able or not to
perform the tasks it is expected to perform.</p>
      <p>In addition to he node status information, Cyber-ARGUS
must collect further data in order to calculate the cyber impact.
An example is information about security, which includes
attacks events, systems’ abuses, etc. This information can be
collected from intrusion detection and prevention systems,
firewall logs, anti-virus, and other security log system. One
important source for this type of data are application and
database logs, which can provide a view about how resources
are used within the system (e.g., what users logged in, which
resource types they used, etc.).</p>
      <p>The data collection is one aspect of this phase. The other
is the need for correlating and inferring relevant information.
To accomplish this, the mission analyst needs to define a
set of trigger events (situations), using a language such as
the Semantic Web Rule Language (SWRL). SWRL extends
a set of OWL axioms to include Horn-like rules, which
can be used in conjunction with the OWL knowledge base.
The expressiveness achieved by this rule scheme is a key
point ensuring the framework’s ability to capture aspects that
cannot be easily captured using OWL, such as utilization
of resources, mission requirements, and others. Furthermore,
using the aforementioned rules Cyber-ARGUS can classify
from large data sets what elements are relevant, and store it to
be used in the next phase, when the cyber impact is assessed.</p>
      <p>IV. CYBER IMPACT ASSESSMENT</p>
      <p>
        The cyber impact assessment is defined by four sub-tasks.
The first is to generate the Impact Graph, which is a
dependence graph [
        <xref ref-type="bibr" rid="ref29">29</xref>
        ] that represents mission, as well as the
dependence (mission and IT domain) and the influence that
each node has on the mission.
      </p>
      <p>
        The framework will generate three impact graphs, each one
representing a security viewpoint (Confidentiality, Integrity,
and Availability - CIA). To generate these graphs, the mission
analyst needs to inform which tasks he would like to assess
and how deep the analysis should be. Using this information,
the tasks and assets will be mapped using SPARQL queries
[
        <xref ref-type="bibr" rid="ref30">30</xref>
        ]. Another key aspect of the framework is its ability
to perform plausible reasoning with incomplete data, which
enables principled handling of uncertainty. This is achieved
by the creation of a Bayesian network (BN) [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ] from the
impact graph, which we explain later in this Section.
      </p>
      <p>The most critical step in impact assessment is how to
measure health node - the ability of the node to provide
the services it is responsible for. Our framework measures it
through the operational capacity (OC), which is the ability
to provide the required resources and services with a certain
level of quantity, quality, effectiveness, and cost. In
CyberARGUS, this is calculated separately for each of the security
views (CIA), enabling the generation of different perspectives.</p>
      <p>The OC calculation is presented in Equation 1 below, where
OCx(i) represents the operational capacity of node i; secx(i)
represents its security index, and expx(i) represents its exploit
index. The security index x denotes the security situation of a
node for a specific perspective (i.e., confidentiality, integrity,
or availability).</p>
      <p>OCx(i) = cost ⇥ secx(i) ⇥ explx(i)
(1)</p>
      <p>
        Using the same approach of Kim and Kang [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ],
CyberARGUS uses TOPSIS to aggregate a set of node attributes
to define an index. In Cyber-ARGUS, the attributes and the
associated weights used to generate the security index are
provided by the mission analyst and collected by the event
manager.
      </p>
      <p>TOPSIS provides a choice between the shortest geometric
distance from the positive ideal solution and the longest
geometric distance from the negative ideal solution. It is
crucial because in most network attributes the highest and
lowest values convey little or no useful meaning for calculating
the security index. An example is the interface’s load, in which
the highest load value means that interface cannot answer
new packets; and the lowest value simply indicates that the
interface is not working.</p>
      <p>
        The security index generation starts with creation of a
decision matrix (xij)mxn, where each of the m nodes (i) and
their n associated attributes (j) are stored. The next step is the
normalization of sensor data (Equation 2), which is required
for ensuring consistency in additive aggregation techniques.
In Cyber-Argus, all attributes are normalized using vector
normalization [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ], where xij is the value of the jth attribute
of the ith node (1  i  m, 1  j  n).
      </p>
      <p>zij =</p>
      <p>xij
qPn</p>
      <p>j=1 xi2j</p>
      <p>Using normalization matrix, the attributes weights are
applied. In the Equation 3, wj is the weight of the jth attribute.</p>
      <p>vij = wj ⇥ zij</p>
      <p>
        The next step is the calculation of zenith (A*) and nadir (A-)
values, using the equations Equation 4 and Equation 5, where
I0 is associated with benefit criteria, and I00 is associated with
cost criteria [
        <xref ref-type="bibr" rid="ref31">31</xref>
        ]. As presented in [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], max and min values (for
performance reasons) are defined by the analyst, based on the
maximum and minimum values accepted to accomplish target
mission.
      </p>
      <p>A⇤ = v1⇤ , ..., vn⇤ = (maxj vij |i 2 I0), (minj vij |i 2 I00) (4)
A</p>
      <p>= v1 , ..., vn = (minj vij |i 2 I0), (maxj vij |i 2 I00) (5)
In the sequence, the Euclidean distances are calculated using
Equations 6 and 7.
(2)
(3)
(6)
(7)
(8)
the existence of active path attacks to the stored node’s
vulnerabilities. To compute the index, the possible exploit
vulnerabilities are considered via their respective vulnerability
impact factor (V), as presented in Equation 9.</p>
      <p>n
expl(i) = [ Y (1
k=0</p>
      <p>
        In Equation 9, i represents the cyber-node and n, the number
of vulnerabilities that have a known exploit path that can be
explored. This index has the same principles of metrics defined
in [
        <xref ref-type="bibr" rid="ref32">32</xref>
        ], where the more high score vulnerabilities a node has,
the smaller its OC will be and, consequently, the worst will
be its ability to provide contracted services reliably.
      </p>
      <p>
        OC’s definition is an essential step in Cyber-ARGUS, as
it reflects the model’s beliefs. That is, a higher OC means a
higher likelihood of accomplishing the mission’s goals. The
propagation of these beliefs is performed using a BN. In our
model, cyber-asset is a deterministic rank node and its values
are based on the calculated OC. To simplify the composition
of a BN, the OCs will be discretized in three parametric states:
high, medium, and low operational capacity. Belief on the
reliability of services and tasks are also represented as
probabilistic nodes, which states are: unreliable, medium reliability,
and reliable. The range of each one of aforementioned states
is calculated as defined in [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ].
      </p>
      <p>
        The values of cyber-nodes (i.e. their state variables) are used
to assess the beliefs on the reliability of service and tasks. A
main issue is how to generate the conditional probability tables
(CPT) for the service and task nodes, since it requires
timeconsuming work from analysts [
        <xref ref-type="bibr" rid="ref33">33</xref>
        ]. For example, considering
a node that has five parent nodes and each node has two
different states, its associated CPT will have 63 values to
be elicited (25-1, since the last value can be calculated).
Cyber-ARGUS addresses this issue by using an automated
approach to generate CPTs, as defined in Fenton and Neil
[
        <xref ref-type="bibr" rid="ref33">33</xref>
        ]. A TNORMAL distribution is used to define the weighted
rank node functions, and to calculate the CPTs. Equation 10
illustrates this approach, where X is the target variable and Y
is the conditional evidence.
      </p>
      <p>p(X|Y ) = hF U N C,</p>
      <p>Pn 1
i=1(wi)
, 0, 1i
(10)</p>
      <p>A TNORMAL is similar to a NORMAL distribution, but
with its values enclosed within a finite range. In the
aforementioned equation, the first parameter is the mean of distribution,
which is calculated using WMIN (Equation 11) and WMAX
(Equation 12). The second parameter is the variance, which is
calculated using the weight of influence that each parent-node
has over the target variable. The last two parameters (values
0 and 1) are the boundary defined for p(X|Y ).</p>
      <p>W M IN = min8 i=1,...,n
W M IN = max8 i=1,...,n
h wiXi+P</p>
      <p>wi+(ni6=1j)(Xj) i
h wiXi+P
wi+(ni6=1j)(Xj) i
(11)
(12)
uv m
Dj+ = tu(X(vij</p>
      <p>i=1
vu m
Dj = tuX(vij
i=1
vi⇤ )2), j = 1, ..., n
vi )2), j = 1, ..., n</p>
      <p>Finally, the last step is the calculation of relative closeness
to ideal solution (T j⇤ ). In our framework, this metric represents
the security index of a node, secx(i), and is calculated using
Equation 8. An alternative w is better than y, when T w⇤ &gt; T y⇤ .
secx(j) = T j⇤ =</p>
      <p>Dj
Dj + Dj+</p>
      <p>The second component of OC is the exploit index, expl(i).
To calculate it, Cyber-ARGUS retrieves all security
information from KB (vulnerability and exploit paths), and verifies</p>
      <p>In Cyber-ARGUS, weights can be collected during Mission
Modeling, using service-level information from the mission
analyst. However, they can also be set manually by the analyst,
so to reflect his level of uncertain about the fact. In general, the
network weight is proportionally inverse to node’s distance.
For example, if node A hosts a service, its weight (wk) is
set to 1 (one). However, if node B is a neighbor of node A
and does not host the target service, the framework applies
Equation 13, where r is the distance of hosted node.
wk =</p>
      <p>Further, when a dependent node (service or task) connects
parent nodes using OR relationship, the WMAX function is
used. Conversely, if it has an AND relationship, the framework
uses the WMIN function.</p>
      <p>The cyber impact on the mission is calculated after the belief
propagation process, which occurs step-by-step from
cyberassets to services and from services to tasks. A more formal
representation of impact on the mission beliefs, imp(x), is
presented in Equation 14, where its values are calculated
from a joint probability distribution. In the equation, X is the
mission result node and Y is the set of parents of this node.
imp(X) = p(X|Y ) = p(Y |X) ⇥
n
Y p(Xi)
i=1</p>
    </sec>
    <sec id="sec-2">
      <title>V. STUDY CASE - AIR TRAFFIC SCENARIO</title>
      <p>To evaluate the framework, we have independently
developed an air traffic scenario representing the Air Traffic Control
operations in the Campos Basin. This is a petroleum rich
area in the Rio de Janeiro state that is responsible for 80%
of Brazil’s petroleum production, which is prospected and
explored from oceanic fields. The operation relies on heavy
helicopter traffic between the continent and oceanic fields
during daytime, with an average of 50 minutes per flight.</p>
      <p>To support this operation, Brazil has an Air Control Center
(ACC) in Macae´ (Rio de Janeiro). This center has a radar
station that supports the surveillance service within the
terminal. However, the oil platforms are located at sites that are
more than 60NM from Macae´. Helicopter flights are carried
out at low altitude, so there is no radar coverage close to the
oil platforms and thus the Air Traffic Service (ATS) has to
be based on non-radar procedures. This significantly reduces
efficiency of air operations.</p>
      <p>The Brazilian Government solution currently under study
includes adopting the Automatic Dependent
SurveillanceBroadcast (ADS-B) technology. The strategy is to supplement
radar coverage in the oceanic air space. The ADS-B operation
is based on using radios to transmit and receive aircraft
position information generated through the satellite GNSS
GPS via a data link. The radios work as relay agents, sending
positional information to a central node. This data is then
integrated to an ADS-B Server, which supports air traffic
controllers in managing the air traffic.
(13)
(14)</p>
      <p>
        This new technology has a set of security issues. A complete
survey of ADS-B’s vulnerabilities, different ways to exploit it,
and the importance in protecting it is presented in [
        <xref ref-type="bibr" rid="ref34">34</xref>
        ].
      </p>
      <p>
        Due to its criticality and vulnerability, the Campos Basin’s
scenario is a good candidate to validate the Cyber-ARGUS
framework. The scenario was implemented using a complex,
distributed simulation/emulation environment, the C2
Collaborative Research Testbed [
        <xref ref-type="bibr" rid="ref25">25</xref>
        ].
      </p>
      <p>The C2 Collaborative Research Testbed scenario includes all
ADS-B radio-stations existing in the area, a set of simulated
helicopters. It provides a realistic environment, suitable for
evaluating all phases of the Cyber-ARGUS framework. In the
experiments, Cyber-ARGUS was used to build the Impact
Dependence Graph, which has all tasks, services and nodes
required to asses the cyber-impact on the typical mission with
that scenario. As an example, to accomplish goal ”M1” it is
required to perform tasks ”Manage Traffic” and ”Deconflict
Traffic,” which were part of the experiments. The resulting
graph was used to build the BN, and the services and tasks
beliefs were calculated using WMIN and WMAX function,
enabling that impact on the mission can be calculated. The
preliminary results of these experiments are discussed in
Section VI below.</p>
    </sec>
    <sec id="sec-3">
      <title>VI. PRELIMINARY RESULTS AND DISCUSSION</title>
      <p>In the Cyber-ARGUS evaluation experiments, each round
consumed approximately two hours. During this time, a set
of attributes of the cyber nodes were collected and their
associated OCs were calculated. The OCs were then used to
feed the BN and calculate the impact.</p>
      <p>In this initial evaluation, the focus was in measuring the
availability attributes in response to a campaign of
Deny-ofService attack (DoS). A DoS is an attempt to make a machine
or network resource unavailable to its intended users. This
attack aims to interrupt the service that is required to be
performed for achieving a given mission task. The campaign
was performed during three times, and in each iteration the
required values were collected and the final impact assessed
using the full Cyber-ARGUS process. In the first attack, the
target included the ADS-B radios P20 and MAC. These two
radios are important to the mission because they cover most
of the oil platforms. When they fail, some platforms lose
their ADS-B coverage, which results in the ATC reverting
back to a lesser operation mode with increased separation
between aircraft. The second attack aimed to deny all network,
and all radio’s nodes and servers were attacked. In the last
campaign, the attack was specifically against the ATC-SIM.
This is a server responsible for processing all tracks, fusing
them and displaying on the ATC’s visualization. It provides all
information needed for the controllers’ situational awareness.</p>
      <p>
        The results of the first and second attacks are shown in the
Figure 1. In the graphic, the beliefs for nodes OC, service
and goal are represented. All values were normalized, and the
most important information is the trend of attributes. Note
that Mission Goal (M1) is completely insensitive to variations
in the P15 radio. However, attacks on nodes MAC and P20
Fig. 2. Attack on ATC Server
(between 100 and 150 slot-time) resulted in a decrease in the
track service and the goal beliefs. This shows that OC is a
good estimator of mission assurance [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ].
      </p>
      <p>The last attack was more critical, as it happens on the main
server that supports the mission. The results clearly show that
all process automation was denied, decreasing the belief that
mission can be performed with the same level of success than
in a normal situation. Figure 2 shows that when the server
is down, controllers revert back to conventional operation.
This results in a great decrease of operational performance,
although the mission still continues to happen. As in the early
example, during the ATC attack the trend line is the same to
the server, to the services it hosts, and to the mission goal.</p>
      <p>VII. FINAL REMARKS</p>
      <p>Cyber-ARGUS is a framework that enables the calculation
of the impact that actions within the cyber domain have
over elements in the operational domain. This allows for a
large spectrum of analysis on complex Command and Control
operations (Military, Civil, and others), where events that
happen in one dimension will be reflected in other dimensions.
The framework also enables a better understanding of the
critical events that affect the environment and have impact
on the mission. This capability can also be used to develop
more accurate defense/offensive plans and scenarios in critical
applications.</p>
      <p>In this paper, we showed the use of a knowledge base to
generate the impact graph, which is then used to propagate
the nodes effects beliefs to services and tasks.</p>
      <p>This is a research in progress in an area where clear answers
are usually not attainable, mostly due to the complexity but
also to the subjectivity involved in assessing impact in an
ongoing operation. Currently the framework is being extended
to provide new capabilities and allow its use in increasingly
richer and more complex scenarios. One of the limitations
of the current implementation is its inability to change the
network topology and reflect the effect inside the BN, which
is an important aspect given the constant network changes
due to sensor reallocation, losses, and similar phenomena.
Another limitation is the lack of a proper modeling of the
enemy behavior (attack graph), which is needed to calculate
the exploit index, and generate accurate information to
represent the OC index. Finally, it’s necessary more complex and
different scenarios, providing confidence to apply method in
general Command and Control scenarios.</p>
      <p>ACKNOWLEDGMENTS</p>
      <p>The authors would like to thank VT MA¨ K for providing
all tools and support to develop the Testbed. They would also
express their gratitude to the anonymous reviewers for their
careful work and insightful comments.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>M. G. W. T.</given-names>
            <surname>Lord</surname>
          </string-name>
          , “
          <article-title>Cyberspace operations: Air force space command takes the lead,” High Frontier -</article-title>
          <source>The Journal for Space &amp; Missile Professionals</source>
          , vol.
          <volume>5</volume>
          , pp.
          <fpage>3</fpage>
          -
          <lpage>5</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>V. N. E. Brown,</surname>
          </string-name>
          “
          <article-title>Difficulties encountered as we evolve the cyber landscape for the military</article-title>
          ,
          <source>” High Frontier - The Journal for Space &amp; Missile Professionals</source>
          , vol.
          <volume>5</volume>
          , pp.
          <fpage>6</fpage>
          -
          <lpage>8</lpage>
          ,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>A. B.</given-names>
            <surname>Barreto</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Costa</surname>
          </string-name>
          , and E. Yano, “
          <article-title>A semantic approach to evaluate the impact of cyber actions to the physical domain,” in Semantic Technologies for Intelligence, Defense, and</article-title>
          <string-name>
            <surname>Security</surname>
          </string-name>
          <year>2012</year>
          .,
          <string-name>
            <given-names>P. C. G.</given-names>
            <surname>Costa and K. B. Laskey</surname>
          </string-name>
          , Eds., vol.
          <volume>966</volume>
          , no.
          <source>ISSN 1613-0073</source>
          . CEUR-WS,
          <year>October 2012</year>
          , pp.
          <fpage>64</fpage>
          -
          <lpage>71</lpage>
          . [Online]. Available: http://ceur-ws.
          <source>org/</source>
          Vol-
          <volume>966</volume>
          /
          <article-title>STIDS2012 T08 BarretoEtAl EvaluateImpactOfCyberActions</article-title>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>D. E.</given-names>
            <surname>Denning</surname>
          </string-name>
          , “
          <article-title>An intrusion-detection model</article-title>
          ,
          <source>” IEEE Transactions on Software Engineering</source>
          , vol.
          <volume>13</volume>
          , pp.
          <fpage>222</fpage>
          -
          <lpage>232</lpage>
          ,
          <year>1987</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>T.</given-names>
            <surname>Bass</surname>
          </string-name>
          , “
          <article-title>Multisensor data fusion for next generation distributed intrusion detection systems</article-title>
          ,” in IRIS National Symposion,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>E</given-names>
            <surname>´</surname>
          </string-name>
          . Bosse´,
          <string-name>
            <given-names>J.</given-names>
            <surname>Roy</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Wark</surname>
          </string-name>
          ,
          <article-title>Concepts, models, and tools for information fusion</article-title>
          .
          <source>Artech House ˆ eBoston Boston</source>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>G.</given-names>
            <surname>Jakobson</surname>
          </string-name>
          , “
          <article-title>Mission cyber security situation assessment using impact dependency graphs,” in Information Fusion (FUSION</article-title>
          ),
          <source>2011 Proceedings of the 14th International Conference on, 2011</source>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>8</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>B.</given-names>
            <surname>Schneier</surname>
          </string-name>
          , “
          <article-title>Attack trees: Modeling security threats,” Dr. Dobb's journal</article-title>
          ,
          <year>December 1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>S.</given-names>
            <surname>Jajodia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Noel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kalapa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Albanese</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Williams</surname>
          </string-name>
          , “
          <article-title>Cauldron mission-centric cyber situational awareness with defense in depth,”</article-title>
          <source>in MILITARY COMMUNICATIONS CONFERENCE, 2011 - MILCOM</source>
          <year>2011</year>
          ,
          <year>2011</year>
          , pp.
          <fpage>1339</fpage>
          -
          <lpage>1344</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>S.</given-names>
            <surname>Musman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tanner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Temin</surname>
          </string-name>
          , E. Elsaesser, and L. Loren, “
          <article-title>Computing the impact of cyber attacks on complex missions</article-title>
          .
          <source>” in 2011 IEEE International Systems Conference (SysCon)</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>46</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Musman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tanner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Temin</surname>
          </string-name>
          , E. Elsaesser, and L. Loren, “
          <article-title>A systems engineering approach for crown jewels estimation and mission assurance decision making</article-title>
          .”
          <source>in IEEE Symposium on Computational Intelligence in Cyber Security (CICS)</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>J.</given-names>
            <surname>Holsopple</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. J.</given-names>
            <surname>Yang</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Sudit</surname>
          </string-name>
          , “
          <article-title>Tandi: threat assessment of network data and information</article-title>
          ,”
          <source>in Proceedings of SPIE, Defense and Security Symposium</source>
          , vol.
          <volume>6242</volume>
          ,
          <year>April 2006</year>
          , pp.
          <fpage>114</fpage>
          -
          <lpage>129</lpage>
          . [Online]. Available: http://dx.doi.org/10.1117/12.665288
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>Q.</given-names>
            <surname>Changwen</surname>
          </string-name>
          and
          <string-name>
            <given-names>H.</given-names>
            <surname>You</surname>
          </string-name>
          , “
          <article-title>A method of threat assessment using multiple attribute decision making,”</article-title>
          <source>in Signal Processing</source>
          ,
          <year>2002</year>
          6th International Conference on, vol.
          <volume>2</volume>
          ,
          <issue>2002</issue>
          , pp.
          <fpage>1091</fpage>
          -
          <lpage>1095</lpage>
          vol.
          <volume>2</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>C. L.</given-names>
            <surname>Hwang</surname>
          </string-name>
          ,
          <article-title>Multiple Attribute Decision Making: Methods and Applications, ser</article-title>
          .
          <source>Lecture Notes in Economics &amp; Mathematical Systems</source>
          . Springer-Verlag,
          <year>1981</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>N.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Zhang</surname>
          </string-name>
          , H. Zhang, and W. Liu, “
          <article-title>Security assessment for communication networks of power control systems using attack graph and mcdm,” Power Delivery, IEEE Transactions on</article-title>
          , vol.
          <volume>25</volume>
          , no.
          <issue>3</issue>
          , pp.
          <fpage>1492</fpage>
          -
          <lpage>1500</lpage>
          ,
          <year>2010</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>A.</given-names>
            <surname>Kim and M. H. Kang</surname>
          </string-name>
          , “
          <article-title>Determining asset criticality for cyber defense</article-title>
          ,
          <source>” ONR, Memorandum Report 55-6334</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>Y.-G.</given-names>
            <surname>Kim</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Jeong</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.-H.</given-names>
            <surname>Park</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lim</surname>
          </string-name>
          , and D.
          <string-name>
            <surname>-K. Baik</surname>
          </string-name>
          ,
          <source>Modeling and Simulation for Security Risk Propagation in Critical Information Systems, ser. Lecture Notes in Computer Science</source>
          . Springer Berlin Heidelberg,
          <year>2007</year>
          , vol.
          <volume>4456</volume>
          , ch.
          <source>Computational Intelligence and Security</source>
          , pp.
          <fpage>858</fpage>
          -
          <lpage>868</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>J.</given-names>
            <surname>Pearl</surname>
          </string-name>
          , “
          <article-title>Markov and bayes networks: A comparison of two grapgraph representations of probabilistic knowledge</article-title>
          ,” University pf california,
          <source>Tech. Rep.</source>
          ,
          <year>1986</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>J. Wu</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Yin</surname>
            , and
            <given-names>Y.</given-names>
          </string-name>
          <string-name>
            <surname>Guo</surname>
          </string-name>
          , “
          <article-title>Cyber attacks prediction model based on bayesian network,” in Parallel and Distributed Systems (ICPADS</article-title>
          ),
          <year>2012</year>
          IEEE 18th International Conference on,
          <year>2012</year>
          , pp.
          <fpage>730</fpage>
          -
          <lpage>731</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>S. van Gosliga</surname>
          </string-name>
          ,
          <string-name>
            <surname>R. van Katwijk</surname>
          </string-name>
          , and
          <string-name>
            <surname>P. van Koningsbruggen</surname>
          </string-name>
          , “
          <article-title>Realtime traffic monitoring with bayesian belief networks</article-title>
          ,
          <source>” in 11th World Congress on Intelligent Transport Systems (ITS-2005)</source>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J.</given-names>
            <surname>Li</surname>
          </string-name>
          ,
          <string-name>
            <given-names>X.</given-names>
            <surname>Ou</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Rajagopalan</surname>
          </string-name>
          , “
          <article-title>Uncertainty and risk management in cyber situational awareness,” in Cyber Situational Awareness, ser</article-title>
          . Advances in Information Security,
          <string-name>
            <given-names>S.</given-names>
            <surname>Jajodia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Liu</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Swarup</surname>
          </string-name>
          , and
          <string-name>
            <given-names>C.</given-names>
            <surname>Wang</surname>
          </string-name>
          , Eds. Springer US,
          <year>2010</year>
          , vol.
          <volume>46</volume>
          , pp.
          <fpage>51</fpage>
          -
          <lpage>68</lpage>
          . [Online]. Available: http://dx.doi.
          <source>org/10.1007/978-1-4419-0140-8 4</source>
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>A.</given-names>
            <surname>Singhal</surname>
          </string-name>
          and
          <string-name>
            <given-names>X.</given-names>
            <surname>Ou</surname>
          </string-name>
          , “
          <article-title>Security risk analysis of enterprise networks using probabilistic attack graphs,” National Institute of Standards and Technology</article-title>
          ,
          <source>Tech. Rep.</source>
          ,
          <year>2001</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>S.</given-names>
            <surname>Duan</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.</given-names>
            <surname>Babu</surname>
          </string-name>
          , “
          <article-title>Proactive identification of performance problems,” in Proceedings of the 2006 ACM SIGMOD international conference on Management of data, ser</article-title>
          .
          <source>SIGMOD '06</source>
          . New York, NY, USA: ACM,
          <year>2006</year>
          , pp.
          <fpage>766</fpage>
          -
          <lpage>768</lpage>
          . [Online]. Available: http://doi.acm.
          <source>org/10</source>
          .1145/1142473.1142582
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <article-title>DoD, DODAF</article-title>
          .
          <source>DoD Architecture Framework Version 2</source>
          .
          <fpage>0</fpage>
          - Volume 1:
          <string-name>
            <surname>Introduction</surname>
          </string-name>
          , Overview, and
          <string-name>
            <surname>Concepts</surname>
          </string-name>
          .,
          <source>DoD Std</source>
          .,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <surname>A. B. Barreto</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Hieb</surname>
          </string-name>
          , and E. Yano, “
          <article-title>Developing a complex simulation environment for evaluating cyber attacks</article-title>
          ,” in Interservice/Industry Training, Simulation, and Education Conference (I/ITSEC)
          <year>2012</year>
          ., vol.
          <volume>12248</volume>
          ,
          <year>December 2012</year>
          , pp.
          <fpage>1</fpage>
          -
          <lpage>9</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>A. DAmico</surname>
          </string-name>
          , L.
          <string-name>
            <surname>Buchanan</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Goodall</surname>
            , and
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Walczak</surname>
          </string-name>
          , “
          <article-title>Mission impact of cyber events: Scenarios and ontology to express the relationships between cyber assets, missions, and users</article-title>
          .
          <source>” AFRL/RIEF, Tech. Rep. OMB No</source>
          .
          <volume>0704</volume>
          -
          <issue>0188</issue>
          ,
          <year>December 2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>C. J.</given-names>
            <surname>Matheus</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. M. Kokar</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Baclawski</surname>
            ,
            <given-names>J. A.</given-names>
          </string-name>
          <string-name>
            <surname>Letkowski</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Call</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Hinman</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Salerno</surname>
            , and
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Boulware</surname>
          </string-name>
          , “SAWA:
          <article-title>An assistant for higher-level fusion and situation awareness</article-title>
          ,
          <source>” Proceedings of SPIE</source>
          , vol.
          <volume>5813</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>75</fpage>
          -
          <lpage>85</lpage>
          ,
          <year>2006</year>
          . [Online]. Available: http://link.aip.org/link/?PSI/5813/75/1\&amp;Agg=doi
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28]
          <string-name>
            <surname>OMG</surname>
          </string-name>
          ,
          <article-title>Business Process Model and Notation (BPMN) 2</article-title>
          .0, http://www.omg.org/spec/BPMN/2.0,
          <string-name>
            <given-names>OMG</given-names>
            <surname>Std</surname>
          </string-name>
          .,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>F.</given-names>
            <surname>Balmas</surname>
          </string-name>
          , “
          <article-title>Displaying dependence graphs: a hierarchical approach,” in Proceedings of the Eighth Working Conference on Reverse Engineering (WCRE'01), ser</article-title>
          .
          <source>WCRE '01</source>
          . Washington, DC, USA: IEEE Computer Society,
          <year>2001</year>
          , pp.
          <fpage>261</fpage>
          -. [Online]. Available: http://dl.acm.org/citation.cfm?id=
          <volume>832308</volume>
          .
          <fpage>837144</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>E.</given-names>
            <surname>Prud</surname>
          </string-name>
          and
          <string-name>
            <given-names>A.</given-names>
            <surname>Seaborne</surname>
          </string-name>
          , SPARQL
          <volume>1</volume>
          .1 Overview, W3C Std.,
          <year>2008</year>
          . [Online]. Available: http://www.w3.org/TR/rdf-sparql-query/
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>K.</given-names>
            <surname>Yoon</surname>
          </string-name>
          and
          <string-name>
            <given-names>C.</given-names>
            <surname>Hwang</surname>
          </string-name>
          ,
          <article-title>Multiple Attribute Decision Making An Introduction</article-title>
          . SAGE,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>B. J.</given-names>
            <surname>Argauer</surname>
          </string-name>
          and
          <string-name>
            <given-names>S. J.</given-names>
            <surname>Yang</surname>
          </string-name>
          , “
          <article-title>Vtac: virtual terrain assisted impact assessment for cyber attacks</article-title>
          ,”
          <source>in Proc. SPIE 6973</source>
          ,
          <string-name>
            <surname>Data</surname>
            <given-names>Mining</given-names>
          </string-name>
          , Intrusion Detection, Information Assurance, and
          <string-name>
            <surname>Data Networks Security</surname>
            ,
            <given-names>B. V.</given-names>
          </string-name>
          <string-name>
            <surname>Dasarathy</surname>
          </string-name>
          , Ed., vol.
          <volume>6973</volume>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>N.</given-names>
            <surname>Fenton</surname>
          </string-name>
          and
          <string-name>
            <given-names>M.</given-names>
            <surname>Neil</surname>
          </string-name>
          ,
          <article-title>Risk Assessment and Decision Analysis with Bayesian Network</article-title>
          . CRC Press,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>D.</given-names>
            <surname>McCallie</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Butts</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R.</given-names>
            <surname>Mills</surname>
          </string-name>
          , “
          <article-title>Security analysis of the adsb implementation in the next generation air transportation system</article-title>
          .”
          <source>International Journal of Critical Infrastructure Protection</source>
          , vol.
          <volume>4</volume>
          , pp.
          <fpage>78</fpage>
          -
          <lpage>87</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>