<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>A Semantic Approach to Evaluate the Impact of Cyber Actions on the Physical Domain</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alexandre de Barros Barreto</string-name>
          <email>adebarro@c4i.gmu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Edgar T. Yano</string-name>
          <email>yano@ita.br</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Instituto Tecnolo ́gico de Aerona ́utica</institution>
          ,
          <addr-line>Sa ̃o Jose ́ dos Campos, SP</addr-line>
          ,
          <country country="BR">Brazil</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Instituto Tecnolo ́gico de Aerona ́utica</institution>
          ,
          <addr-line>Sa ̃o Jose ́ dos Campos, SP</addr-line>
          ,
          <country country="BR">Brazil</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>-Evaluating the impact that events within the cyber and what it means to the overall mission. Existing tools and domain have on a military operation and its critical infrastruc- methodologies cannot provide this level of information, and ture is a non-trivial question, which remains unanswered so are not suitable to support complex cyber threat assessment fkaery iinssusepiutendoefrltyhiengvtahriisouqsuersetsieoanrcish thefefodritfsficaudltdyreisnsicnogrrietl.atTinhge in real situations. This is a major gap that to our knowledge cyber and physical behaviors in an integrated view, thus allowing has not been successfully filled, in spite of the relatively large for real-time analysis. This paper addresses the issue with the body of research focused on the subject. development of an ontology-based framework in which the cyber This paper addresses this gap by proposing a semantic and physical behaviors are integrated in a consolidated view, framework that fuses physical and cyber data collected from tuescihnngoalogcoiems.bIinnaotuiornapopfrooapcehn, tshtaenmdaisrsdiosnparnodtoictoslpshaynsidcasleamspanectitcs existing sensors and retrieving information that is relevant are modeled using a business process language (e.g., BPMN) to the assessment of cyber impact. It is designed to support and an information infrastructure based on Simple Network analysts with an integrated view, one that correlates actions in Management Protocol (SNMP). In this scheme, changes in the the cyber domain with effects in other domains, allowing the environment are captured using the output of sensor components evaluation of its impact on the operational objectives. eaxnidstiinngtegirnattehde ainnafrlyassitsruocfttuhree.acIcnruoirndgerdattoa, ewnesuhraevea dceovmeloppleetde The proposed framework and its main aspects are illustrated a Cyber Situation ontology (in OWL) and a methodology for and evaluated via a simulated air traffic scenario, which mapping the cyber and the physical domains. In this framework, includes a large number of simulated flights. mission data from the environment is retrieved and fused using This paper is organized as follows. Section II presents the an engine based on the Semantic Web Rule Language (SWRL). main concepts necessary to understand the framework being Twhaye tohuattpuontloyfththeismporsotcimespsoirstathnetninpforremseanttieodn tnoeeadnedantaolysustppinorat proposed, as well as a sample of the most relevant approaches his/her decisions is shown. To validate our approach, a real air attained so far to address the problem. Section III describes traffic scenario was modeled and many simulated flights were the framework for evaluating the impact of a cyber attack on generated to support of our experiments. an operation occurring in the physical domain. The approach is discussed in Section IV, and illustrated with an analysis I. INTRODUCTION of a fictitious air traffic scenario build specifically to evaluate With the increasing automation of processes and systems our research. Finally, Section V presents a few considerations that are part of critical infrastructures supporting military and and issues that must be addressed in future research aimed to vital civilian operations, the cyber domain became one of most improve the approach. important aspects in strategic planning. Society's dependence on this domain [1] has reached a point II. BACKGROUND AND RELATED RESEARCH in which it is now considered as a new dimension of war, The main concept to present is mission. As discussed in together with air, land and sea. In this new paradigm, a key [4], a mission is the task (or set of tasks), together with its aspect is to understand how actions performed in the cyber (their) associated purpose, that clearly indicates the action to domain (space and time) affect the operations taking place in be taken assigned to an individual or unit. the other domains, so one can leverage actions in the cyber Three other important concepts are Situation Awareness, Imdomain as tools to achieve the campaign objectives [2], [3] pact Assessment and Threat Assessment. The first, as described Unfortunately, this is no trivial task, since it requires cor- in [5], is the perception of the elements of the environment relating cyber and physical behaviors in an integrated view within a volume of time and space, the comprehension of their that allows tasks to be evaluated in real time. The complexity meaning, and the projection of their status into the near future embedded in this requirement implies, among other things, to enable decision superiority. that an IT manager supporting critical infrastructures must be The second important concept, Impact Assessment, involves able to access all relevant data pertaining to the network and the task of estimating the effects on situations of planned translate it to the support team in a way that allows them or estimated/predicted actions by the participants, including to understand the real impact of cyber threats to the network interactions between action plans of multiple players [6].</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>
        The third and last concept, Threat Assessment, can be
understood as an expression of intention to inflict evil, injury,
or damage. The focus of threat analysis is to assess the
likelihood of truly hostile actions and, if they were to occur,
projected possible outcomes [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ].
      </p>
      <p>
        From a general perspective, the second and third concepts
can be seen as being part of the first, but with a difference
in their focus. More specifically, while impact assessment
looks for an “internal” understanding (i.e., what is happening
and why should I care?), threat assessment seeks the same
understanding from the enemy’s viewpoint (i.e., how they
can hurt us). More important to our research is the fact they
all these concepts imply a means to assess the mission. In
other words, all must go through the process of specifying
and maintaining a reasonable degree of confidence in mission
success, which is linked to the concept of Mission Assurance
[
        <xref ref-type="bibr" rid="ref7">7</xref>
        ].
      </p>
      <p>
        Literature on the subject of measuring effectiveness of a
mission points to two major approaches. The first is to use
the concept of task as the evaluation basis, while the second
instead focuses to the effects [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. The framework presented in
this paper adopts the second approach.
      </p>
      <p>
        The main approach to provide mission understanding
involves using a set of distributed sensors to detect intrusions
and to uncover attack paths. The preliminary research on the
subject is due to Denning [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ] and Bass [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Schneier [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]
proposed the use of an attack-tree to measure effect, which
allows understanding of the relationships between attacks,
as well as how one attack over a cyber asset affects other
assets. In spite of the advances above cited, the problem of
determining the impact of a cyber attack on a (mission) task
still persists, since no methodology exists to effectively map
cyber assets to tasks. Furthermore, these techniques are not
capable of dealing with some common types of cyber attacks,
rendering them unsuitable for impact assessment in the current
state of the art in cyber warfare. For instance, when an attack
is new (e.g. a zero-day attack), its signature is unknown and
there will be no attack-tree associated with it. As a result, it
will be extremely difficult to identify its attack pattern by the
time it occurs.
      </p>
      <p>
        The above limitation illustrates the need for new approaches.
A more comprehensive one would involve identifying attacks,
highlighting significant events and then understanding the
importance of them in a system [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. To assess the importance
of events, one must understand how the process of planning
and implementing a mission works. Topological Analysis of
Network Vulnerability (TVA) [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ] is meant to provide such
understanding. TVA supports an analyst in measuring the
impact of a threat through the evaluation of topological aspects
of the environment. The main weakness of this approach is
the absence of an explicit mapping between the mission and
the infrastructure supporting it. As a result, this becomes yet
another cognitive burden implicitly assigned to the analyst, a
solution that clearly does not scale well with the increasing
complexity of the operational environment.
      </p>
      <p>
        Another related approach can be summarized by the work
on Mission-Oriented Risk and Design Analysis (MORDA)
[
        <xref ref-type="bibr" rid="ref14">14</xref>
        ] and on the Security Optimization Countermeasures Risk
and Threat Evaluation System (SOCRATES) [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ]. In this
approach, all components that exist in the problem (mission,
resources and threats) are mapped and used in the analysis.
However, the mapping process is very complex and requires
continuous iteration with the human analyst (i.e.
human-in-theloop), who needs to provide constant feedback and input to
the methodology. As a consequence of its demand for human
interaction, this approach tends to be applied in the planning
phase, while being less suitable to the more time intensive
environment found in real time decision making scenarios.
      </p>
      <p>
        Another methodology that relates to the problem addressed
in this paper is Cyber Mission Impact Assessment (CMIA) [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ],
[
        <xref ref-type="bibr" rid="ref16">16</xref>
        ]. CMIA presents a way to (manually) associate mission
and infrastructure, and use the resulting association to support
the assessment of mission assurance.
      </p>
      <p>In a typical analytical process using CMIA, each attack is
simulated and its associated impact is calculated. Then, all
attacks and assets are correlated and the paths with the highest
cost are prioritized. The major deficiency of this approach is
its inability to evaluate more than one attack simultaneously,
which prevents an assessment of the synergistic effect of
coordinated attacks. This is a major liability, since in most
cases the enemy would attempt to achieve an overall effect
with parallel attacks that is much greater than the sum of the
isolated effects of these same attacks.</p>
      <p>The above mentioned works are a representative subset
of current research related to evaluation of the impact of
cyber threats, and can thus support the claim that the research
problem remains unsolved. In summary, each approach suffers
from in at least one of the two issues that can be singled out
as the main causes for this situation. The first is the lack of
a correlation (and, in some cases, computation) between the
main components that are needed for impact assessment, the
mission and its supporting infrastructure. The second cause for
failures is the inability to provide real-time analysis of these
two components and their interactions. The proposed
framework is meant to address both, with a unique combination
of semantic technologies, operations research, and simulation,
which we explain in the next Section.</p>
    </sec>
    <sec id="sec-2">
      <title>III. EVALUATING THE IMPACT OF CYBER THREATS</title>
      <p>This paper proposes ARGUS, a new Framework that
evaluate the impact of a cyber attack on a mission. ARGUS is
comprised of four main phases: 1) modeling of mission, 2)
modeling of network architecture, 3) collecting cyber and
mission information, and 4) developing impact assessment.
These phases are depicted in Figure 1.</p>
      <p>As implied in the diagram, the core idea within ARGUS
is to capture the mission and infrastructure information and
consolidate it in an integrated data representation, which
allows for a comprehensive analysis to be performed.</p>
      <sec id="sec-2-1">
        <title>A. Modeling of Mission</title>
        <p>The first phase in ARGUS involves modeling of mission,
which is achieved by the use of a business process language.
The goal of this phase is to capture the most important
information of the mission within the model. Importance here,
of course, is measured with respect to its relevance to impact
assessment, and includes the tasks, relationships between the
tasks, objectives, resources required to develop the mission
and, finally, performer (i.e., entity or set of entities that has
the responsibility to perform the mission).</p>
        <p>
          In our current research, we leveraged previous experience
within our group and made the design decision of capturing
these aspects using the Business Process Modeling Notation
(BPMN) language [
          <xref ref-type="bibr" rid="ref17">17</xref>
          ]. However, any business modeling
language with the ability to capture the information described
above could have been used and, therefore, might be used with
the framework in the future.
        </p>
        <p>
          One of the most important features of the ARGUS is its
reliance on semantic technologies to ensure consistency when
used in multiple domains. Therefore, although a business
modeling language is used as the basis for information elicitation
(BPMN, in the current implementation of the ARGUS), all
information captured is stored in an ontology-based
information representation repository. The ontology supporting the
repository was developed using the most recent version of the
W3C recommended OWL 2 Web Ontology Language [
          <xref ref-type="bibr" rid="ref18">18</xref>
          ]. In
fact, to illustrate the advantages of using an ontology-based
framework, it should be emphasized that we didn’t have to
actually develop a mission ontology from scratch, but we
simply imported and made some adaptations to existing work
by others. That is, the ontology itself is an adaptation of the
one defined in D’Amico et al. [
          <xref ref-type="bibr" rid="ref19">19</xref>
          ], while architecture is based
on that of Mateus et al. [
          <xref ref-type="bibr" rid="ref20">20</xref>
          ].
        </p>
        <p>In our context, the main concept in a mission is activity
(see figure 2). An activity has a set of pre and post conditions
and one goal. His goal is to produce one or more effects over
a resource. An activity can be measure, enabling that can be
understand the state of the mission’s components.</p>
        <p>Due to its main focus on business, BPMN lacks native
support for some of the mission information that needed
to be captured. Thus, we had to extend its basic structure
to accommodate our representational requirements. Figures 2
and 3 illustrate some of the extended attributes (marked with a
circle in the figures), which are present in the mission ontology
supporting the repository.</p>
        <p>The use of a business language (BPMN in the current
implementation) was not only convenient as a development
tool for the framework, but also proved to be rather suitable
for capturing the main aspects of a mission, especially when it
is used in civilian environments such as air traffic management,
nuclear power plants, and others. Its business-oriented notation
made it easier to accommodate the concepts of a mission in
the Air Traffic Domain that we are using in the evaluation
of the research, while also having a relatively straightforward
mapping to the associated concepts in the mission ontology.</p>
        <p>One example of a business-oriented concept being mapped
to the mission ontology is that of a Pool. To model a mission,
an analyst starts by describing the Organizations that
participate in the process of accomplishing the mission. These can be
squadrons, sectors, departments, battalions, or any functional
structure involved with the mission details. Pool is the BPMN
concept used to describe such organizations.</p>
        <p>We expect the currently developed mapping to be relatively
robust when applied along with the framework to other
domains. Table I summarizes of the mapping developed in this
initial phase of our research.</p>
        <p>The ARGUS approach only builds mappings between
automated processes, although BPMN is able to support
nonautomated ones. A service is understood as the entity
responsible for performing tasks (activities), while a system is a
collection of services. To ensure a proper correlation between
business and infrastructure data, the analyst must describe
where the service is provided, using his address and ports.</p>
        <p>The framework supports the identification of relevant
information from raw data captured by the sensors. In order
for this to be accomplished, information regarding the effect,
conditions and service level are described using rules. More
specifically, an effect is the result, outcome, or consequence
of an action (task) over a resource. Further, a condition can
be understood as the state of the environment or of a situation
in which a performer (service) performs or is disposed to
perform an task. Finally, service level refers to the minimum
(or maximum, depending on the requirement) standard that a
service is expected to reach with confidence.</p>
      </sec>
      <sec id="sec-2-2">
        <title>B. Modeling of Network Architecture</title>
        <p>
          The second phase in ARGUS, modeling of network
architecture, is in fact performed almost in parallel with the first. In
this phase, all information about the infrastructure is captured
using Simple Network Management Protocol (SNMP) [
          <xref ref-type="bibr" rid="ref21">21</xref>
          ]
and stored in the ontology-supported information
representation repository. The main concept in the ontology used
to represent the infrastructure is Cyber Asset, which is also
depicted in Figure 3. Cyber Assets are responsible for to host
one or more service (which is who performs the activities
needed by the mission). Through services, ARGUS maps the
infrastructure in mission and vice versa.
        </p>
        <p>Another important concept from BPMN is that of a
performer, which was mapped to the mission ontology as service
(cf. Table I). In BPMN, the performer concept defines the
resource that is responsible for an activity. It can be specified in
the form of a specific individual, a group, an organization role
or position, or an organization. Due to the above mentioned
mapping, in ARGUS performers are services, which explains
the need for analysts to specify the implementation address
during the modeling. In other words, the correlation between
the services and the cyber assets is made automatically by the
framework via SNMP queries, which collect the UDP/TCP
ports of the services via two tables residing in the
Management Information Base (MIB) of each of the network hosts
(tcpConnLocalPort and udpLocalPort).</p>
        <p>
          To build the network archiecture and its variations, the
framework performs queries on the other three tables residing
in each host’s MIB, the ipRouteDest, the ipRouteMetric, and
the ipRouteNextHop. The combination of the information
retrieved from these tables allows the Framework algorithm to
infer the neighbors of the host, as well as the network distance
between the host and nodes that were eventually discovered
via the routing protocol embedded in the framework algorithm.
Finally, the framework uses changes in those attributes (e.g.
nodes added, nodes deleted, changes in nodes IP route metrics,
etc.) as parameters for inferring the network dynamics. Besides
the network information mentioned above, the framework also
uses SNMP to retrieve a set of other infrastructure properties,
such as memory (persistent and volatile) size, operating
system, uptime, etc. It is outside the scope of this paper to explain
in detail the framework algorithms and how each network
parameter is assessed, more information on these details can be
obtained from the work at the GMU/ITA C2 testbed (cf. [
          <xref ref-type="bibr" rid="ref22">22</xref>
          ]).
        </p>
      </sec>
      <sec id="sec-2-3">
        <title>C. Collecting Cyber and Mission Information</title>
        <p>The third phase in ARGUS involves the collection of
relevant information. In this case, the criteria for information
to be considered relevant is related to the value it adds to
the overall understanding of the environment (i.e. how it
improves situation awareness). This assessment is performed
in accordance with the general scheme depicted in Figure 4.</p>
        <p>
          The main concept in the scheme is Situation, which is an
event or set of events that are meaningful to the mission. In
ARGUS, events can be captured in any different ways. In
our first implementation, we can retrieving the data existing
in the SYSLOG Database [
          <xref ref-type="bibr" rid="ref23">23</xref>
          ] or by capturing network
packets via a packet capture (PCAP) interface (e.g.through an
intrusion detection system) [
          <xref ref-type="bibr" rid="ref24">24</xref>
          ]. Once an event is captured,
the framework uses rules to classify it as being part of a
situation. As previously mentioned, these rules will be applied
to information retrieved from the network sensors and inserted
into the framework through the BPMN’s and Ontology’s
interfaces (cf. Figures 2, 3, and 4).
        </p>
        <p>
          The design choice for describing the rules was the Semantic
Web Rule Language (SWRL) [
          <xref ref-type="bibr" rid="ref25">25</xref>
          ]. SWRL extends a set of
OWL axioms to include Horn-like rules, thus enabling
Hornlike rules to be combined with an OWL knowledge base. The
expressiveness achieved by this rule scheme is key to the
framework’s ability to capture aspects that cannot be easily
captured using OWL, such as utilization of resources, mission
requirements, and others.
        </p>
        <p>Once all information needed from the business and
infrastructure is retrieved, the events are captured from the
sensors’ input, and classified in accordance with relevant
situations using rules. Then the framework is ready to evaluate
the impact of the current state of the system on its main
mission. In ARGUS, this evaluation is performed through four
distinct types of analysis: dependence paths, temporal, cost,
and history degradation.</p>
        <p>The first type of analysis, dependence paths, aims to
uncover problems in topology that have the potential to affect the
accomplishment of the mission. The typical questions involved
in this analysis include (but are not limited to) the following:</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>In this state of the system, can the mission goal be reached?</title>
      <p>If task C fails, is there any path left to reach the goal?
The second type of analysis, temporal, seeks to define a
window of interest in which the problem is solvable. The
typical questions that are raised in this type of analysis include
but are not limited to:</p>
    </sec>
    <sec id="sec-4">
      <title>What tasks need to be monitored at time T ?</title>
      <p>How much time is needed to finish the task and
accomplish its objective?</p>
      <p>The third type of analysis, cost, is meant to identify when
the cost starts to become a serious threat to the task execution.
In other words, it evaluates the cost / benefit ratio of each task
with respect to the overall mission. The typical questions to
be answered in this analysis include:</p>
    </sec>
    <sec id="sec-5">
      <title>How much does this task cost? Do the benefits of this task justify the costs involved in its execution?</title>
      <p>If task C is compromised, does an alternative route have
an acceptable cost?</p>
      <p>The last type of analysis, history degradation, has the goal
of understanding how fast the infrastructure is degrading. Its
typical questions can be similar to the ones in each of the
above tasks, but with a focus on the way the infrastructure
assets are degrading and its associated impact on the overall
mission.</p>
      <sec id="sec-5-1">
        <title>D. Developing Impact Assessment</title>
        <p>The fourth phase in ARGUS, impact analysis, is the main
part of the framework. In order for this phase to be executed in
real time, so the impact evaluation would be done as the
mission unfolds, we have developed the reference implementation
depicted in Figure 5.</p>
        <p>The Cyber Situation Awareness engine (CyberSA Engine)
is comprised of six modules. The first is the BPMN Module,
which performs the tasks of getting mission information from
a BPMN file, parsing it, and mapping the retrieved concepts
to the mission ontology.</p>
        <p>The SNMP and SYSLOG modules perform queries on
all hosts and on the SYSLOG Server, respectively. When
the associated answers are received, the module parses and
converts them to the format they will be used in the system.</p>
        <p>Once the four modules above collect and process their
respective information, the result needs to be made available</p>
        <p>
          The PCAP module retrieves event data from the network. in a consistent way so the CyberSA Engine can provide it to
However, analysing the retrieved raw data is a time consuming the users. This consistency is also achieved with the support of
and non-trivial task, so in our implementation we have made semantic technologies, via the implementation of a Semantic
the design decision of using an external tool, TSHARK [
          <xref ref-type="bibr" rid="ref26">26</xref>
          ]. Fusion Module. The main services this module provides are
This tool is a terminal-oriented version of Wireshark designed making inferences and applying rules, which were written by
for capturing and displaying packets when an interactive user analysts using the GUI.
interface is not necessary or not available. It has a set of filters
that produces information in a format that is more readable to
analysts.
        </p>
        <p>
          The Semantic Fusion Module uses two libraries to provide
its features. The first is the OWL-API [
          <xref ref-type="bibr" rid="ref27">27</xref>
          ], a Java API
and reference implementation for creating, manipulating and
serializing OWL Ontologies. The second is Pellet [
          <xref ref-type="bibr" rid="ref28">28</xref>
          ], which
is an OWL 2 reasoner that provides standard and cutting-edge
reasoning services for OWL ontologies.
        </p>
        <p>The last module of the CyberSA Engine is the View Module,
which provides the interface to analysts. The main goals of
this interface are to allow analysts to provide information the
system cannot obtain automatically, and to write the rules used
by the system’s inference engine.</p>
        <p>Figure 6 is an example of a typical form of the system’s
GUI, in this case one that allows the analyst to setup a task. In
the combo box depicted in the figure (named as “Activity”), the
analyst chooses the type of activity he wants to set, as well as
the associated fields - which are shown in a contextual fashion
with support from the mission ontology. In the example, the
analyst chose the activity “FlightStartWarning”, and was then
presented with three fields. In the first field, the analyst is
presented with the resources that he needs to do the task. In
the remaining two fields, the analyst is expected to describe,
using rules in SWRL syntax, how to measure the task progress
and the conditions this measure will be performed.</p>
        <p>By means of this GUI, the system will guide the analyst
through a process in which he will be able to define the
activity, the cost of resources, the service’s SLA, and other
rules that must be defined given the relevant situations. The
View Module also provides classification of the event (i.e. the
situation(s) it pertains to).</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>IV. DISCUSSION</title>
      <p>A simulation of an air traffic scenario was developed to
evaluate the framework, verifying its ability to generate the
relevant situation assessment and present it to the analyst. The
simulation is based on a real scenario, located at the Campos
basin in Brazil, where a heavy helicopter operation is held to
support maritime oil platforms sixty to eighty miles offshore.
The mission described in this scenario thus involves air traffic
service where the aircraft consume the smaller amount of fuel
and the system generates a low number of collision resolution
events. A collision resolution event happens when two aircraft
fly within a distance (vertical or horizontal) that is smaller
than the safety rules defined by law.</p>
      <p>The simulation includes three distinct air traffic services
organizations (cf. Figure 7). The first is the AIS (Aeronautical
Information Service), which has the responsibilities of
inserting the flight plan into the system and getting all clearance
necessary for the aircraft to fly. The second service modeled
is the Radio Station, which gets information on flight tracks
(i.e. aircraft) within its area of coverage and sends it to the
APP (Ground-controlled Approach) Service. Finally, the APP
service performs three main tasks: fuse track information,
present it in a controller view and generate alerts to be used
by a monitoring system.</p>
      <p>
        The simulation was developed using the C2 Simulation
Testbed [
        <xref ref-type="bibr" rid="ref22">22</xref>
        ], a joint project between the C4I Center at
George Mason University (GMU) and the C2 Lab at the
Instituto Tecnolo´ gico de Aerona´utica (ITA) in Brazil. The
testbed allows the emulation of any infrastructure behavior
and the simulation of all aspects of the physical
environment (aircraft flights, collisions, etc). The current evaluation
scenario includes fourteen aircraft that take off from three
different airports and go to the oil platforms. The flight plan
was developed to generate collision warnings, allowing the
framework to generate situations of interest. A view of this
scenario using the C2 Simulation Testbed is presented in
Figure 7.
      </p>
      <p>A major aspect that is needed for the framework to
define relevant situations is the proper definition of the rules
by analysts. Among other things, these rules formally
establish to the system the conditions that restrict the task,
the goal of mission in general, the objective of each task,
and other aspects that are important in filtering the raw
data coming from the sensors. In addition to these aspects,
another key use of rules is to create relations that are not
explicit in the domain. As an example, the link between
cyber assets and services can be defined by this simple rule:
CyberAsset(?y); OntoService(?x); ipv4Address(?x; ?k);
ipv4Address(?y; ?k) ! isH ostingI n(?x; ?y). Therefore, it
is fair to say that the combination of SWRL rules and OWL
2 statements to link the physical and cyber domains is at the
heart of the system’s goal of evaluating mission impact.</p>
    </sec>
    <sec id="sec-7">
      <title>V. FUTURE RESEARCH</title>
      <p>This paper presented an approach for connecting the cyber
and physical domains, with the objective of assessing the
impact that actions in the former have in the latter. This is
research in progress in an area where clear answers are usually
not attainable, mostly due to the complexity as well as to the
level of subjectivity involved in real time impact assessment.
As such, the framework presented here should be seen as a
first step of a steep ladder. Yet, it is a firm step, since after
attempting various approaches we remain convinced that the
solution to this problem relies in a combination of techniques
where semantic technologies and simulation play a major role.</p>
      <p>The software modules, including the ontology and some of
the rules, that together comprise the framework are already
implemented, and we are currently evaluating its performance via
the C2 Simulation Testbed. Preliminary results are promising
and should be available soon. Our future work path includes
aspects such as the usability of the system, and others that rely
on semantic technologies to alleviate the reliance on analysts
to provide domain knowledge in the form of SWRL rules.</p>
    </sec>
    <sec id="sec-8">
      <title>ACKNOWLEDGMENT</title>
      <p>The authors recognize VT MA¨ K and Scalable Network
Technologies for providing the tools and support needed to
develop the Testbed. Our gratitude is also extended to
LatinMedia SA, who provided support for the testbed in Brazil.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>G.</given-names>
            <surname>Eason</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Noble</surname>
          </string-name>
          ,
          <string-name>
            <given-names>and I. N.</given-names>
            <surname>Sneddon</surname>
          </string-name>
          , “
          <article-title>On Certain Integrals of Lipschitz-Hankel Type Involving Products of Bessel Functions,”</article-title>
          <source>Philosophical Transactions of the Royal Society of London. Series A, Mathematical and Physical Sciences</source>
          , vol.
          <volume>247</volume>
          , no.
          <issue>935</issue>
          , pp.
          <fpage>529</fpage>
          -
          <lpage>551</lpage>
          , Apr.
          <year>1955</year>
          . [Online]. Available: http://rsta.royalsocietypublishing.org/ content/247/935/529
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>M.</given-names>
            <surname>Endsley</surname>
          </string-name>
          , “
          <article-title>The application of human factors to the development of expert system for advanced cockpits.” in Annual Meeting of Human Factors and Ergonomics Society</article-title>
          .
          <source>Human Factors Society</source>
          ,
          <year>1987</year>
          , pp.
          <fpage>1388</fpage>
          -
          <lpage>1392</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>J.</given-names>
            <surname>Boyd</surname>
          </string-name>
          , “OODA Loop.
          <article-title>” Center for Defense Information</article-title>
          ,
          <source>Tech. Rep.</source>
          ,
          <year>1995</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <article-title>[4] DoD, DODAF</article-title>
          .
          <source>DoD Architecture Framework Version 2</source>
          .
          <fpage>0</fpage>
          - Volume 1:
          <string-name>
            <surname>Introduction</surname>
          </string-name>
          , Overview, and
          <string-name>
            <surname>Concepts</surname>
          </string-name>
          .,
          <source>DoD Std</source>
          .,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>J.</given-names>
            <surname>Salerno</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Hinman</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Boulware</surname>
          </string-name>
          , “
          <article-title>A situation awareness model applied to multiple domains,”</article-title>
          <source>in Proceedings of SPIE</source>
          , vol.
          <volume>5813</volume>
          ,
          <year>2005</year>
          , p.
          <fpage>65</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>E.</given-names>
            <surname>Bosse</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Roy</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Wark</surname>
          </string-name>
          ,
          <article-title>Concepts, models, and tools for information fusion, A</article-title>
          . House, Ed.
          <source>Artech House</source>
          ,
          <year>2007</year>
          2007.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>S.</given-names>
            <surname>Musman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tanner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Temin</surname>
          </string-name>
          , E. Elsaesser, and L. Loren, “
          <article-title>A systems engineering approach for crown jewels estimation and mission assurance decision making</article-title>
          .”
          <source>in IEEE Symposium on Computational Intelligence in Cyber Security (CICS)</source>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>M. J.</given-names>
            <surname>Fiebrandt</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Mills</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Beach</surname>
          </string-name>
          ., “
          <article-title>Modeling and simulation in the analysis of a joint test and evaluation methodology,” in Spring Simulation Multiconference</article-title>
          , vol.
          <volume>3</volume>
          . Society for Computer Simulation International,
          <year>2007</year>
          , pp.
          <fpage>251</fpage>
          -
          <lpage>256</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>D. E.</given-names>
            <surname>Denning</surname>
          </string-name>
          , “
          <article-title>An intrusion-detection model</article-title>
          ,
          <source>” IEEE Transactions on Software Engineering</source>
          , vol.
          <volume>13</volume>
          , pp.
          <fpage>222</fpage>
          -
          <lpage>232</lpage>
          ,
          <year>1987</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>T.</given-names>
            <surname>Bass</surname>
          </string-name>
          , “
          <article-title>Multisensor Data Fusion for Next Generation Distributed Intrusion Detection Systems</article-title>
          ,” in IRIS National Symposion,
          <year>1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>B.</given-names>
            <surname>Schneier</surname>
          </string-name>
          , “
          <article-title>Attack trees: Modeling security threats,” Dr. Dobb's journal</article-title>
          ,
          <year>December 1999</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>O. S.</given-names>
            <surname>Saydjari</surname>
          </string-name>
          , “Cyber defense: Art to Science.”
          <source>Communications of the ACM - Homeland Security</source>
          , vol.
          <volume>47</volume>
          , no.
          <issue>3</issue>
          ,
          <string-name>
            <surname>March</surname>
          </string-name>
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>S.</given-names>
            <surname>Jajodia</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Noel</surname>
          </string-name>
          , and
          <string-name>
            <given-names>B. O</given-names>
            <surname>'Berry</surname>
          </string-name>
          , “
          <article-title>Topological Analysis of Network Attack Vulnerability</article-title>
          .”
          <source>Managing Cyber Threats</source>
          , vol.
          <volume>5</volume>
          , pp.
          <fpage>247</fpage>
          -
          <lpage>266</lpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>S.</given-names>
            <surname>Evans</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Heinbuch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E.</given-names>
            <surname>Kyle</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Piorkowski</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Wallner</surname>
          </string-name>
          , “
          <article-title>Riskbased systems security engineering: stopping attacks with intention</article-title>
          ,
          <source>” IEEE Security and Privacy</source>
          , vol.
          <volume>2</volume>
          , pp.
          <fpage>59</fpage>
          -
          <lpage>62</lpage>
          ,
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Buckshaw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. S.</given-names>
            <surname>Parnell</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W. L.</given-names>
            <surname>Unkenholz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Parks</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. M.</given-names>
            <surname>Wallner</surname>
          </string-name>
          , and
          <string-name>
            <given-names>O. S.</given-names>
            <surname>Saydjari</surname>
          </string-name>
          , “
          <source>Mission Oriented Risk and Design Analysis of Critical Information Systems,” Military Operations Research</source>
          , vol.
          <volume>2</volume>
          , pp.
          <fpage>19</fpage>
          -
          <lpage>38</lpage>
          ,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>S.</given-names>
            <surname>Musman</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Tanner</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Temin</surname>
          </string-name>
          , E. Elsaesser, and L. Loren, “
          <article-title>Computing the impact of cyber attacks on complex missions</article-title>
          .
          <source>” in 2011 IEEE International Systems Conference (SysCon)</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>46</fpage>
          -
          <lpage>51</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>OMG</surname>
          </string-name>
          ,
          <article-title>Business Process Model and Notation (BPMN) 2</article-title>
          .0, http://www.omg.org/spec/BPMN/2.0,
          <string-name>
            <given-names>OMG</given-names>
            <surname>Std</surname>
          </string-name>
          .,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <article-title>W3C, OWL 2 Web Ontology Language</article-title>
          , http://www.w3.org/TR/owl2- overview/, W3C Std.,
          <year>October 2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>A. D'Amico</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          <string-name>
            <surname>Buchanan</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Goodall</surname>
            , and
            <given-names>P.</given-names>
          </string-name>
          <string-name>
            <surname>Walczak</surname>
          </string-name>
          , “
          <article-title>Mission Impact of Cyber Events: Scenarios and Ontology to Express the Relationships between Cyber Assets, Missions, and</article-title>
          <string-name>
            <surname>Users.</surname>
          </string-name>
          ” AFRL/RIEF, Tech. Rep. OMB No.
          <volume>0704</volume>
          -
          <issue>0188</issue>
          ,
          <year>December 2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>C. J.</given-names>
            <surname>Matheus</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. M. Kokar</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          <string-name>
            <surname>Baclawski</surname>
            ,
            <given-names>J. A.</given-names>
          </string-name>
          <string-name>
            <surname>Letkowski</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          <string-name>
            <surname>Call</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Hinman</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          <string-name>
            <surname>Salerno</surname>
            , and
            <given-names>D.</given-names>
          </string-name>
          <string-name>
            <surname>Boulware</surname>
          </string-name>
          , “SAWA:
          <article-title>An assistant for higher-level fusion and situation awareness</article-title>
          ,
          <source>” Proceedings of SPIE</source>
          , vol.
          <volume>5813</volume>
          , no.
          <issue>1</issue>
          , pp.
          <fpage>75</fpage>
          -
          <lpage>85</lpage>
          ,
          <year>2006</year>
          . [Online]. Available: http://link.aip.org/link/?PSI/5813/75/1&amp;Agg=doi
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J.</given-names>
            <surname>Case</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Fedor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Schoffstall</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Davin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A Simple</given-names>
            <surname>Network Management</surname>
          </string-name>
          <article-title>Protocol (SNMP), The Internet Engineering Task Force (IETF) Std</article-title>
          . RFC 1157, May
          <year>1990</year>
          . [Online]. Available: http://www.ietf.org/rfc/rfc1157.txt
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [22]
          <string-name>
            <surname>A. B. Barreto</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          <string-name>
            <surname>Hieb</surname>
          </string-name>
          , and E. T. Yano, “
          <article-title>Developing a Complex Simulation Environment for Evaluating Cyber Attacks,” in I/ITSEC</article-title>
          . I/ITSEC,
          <year>2012</year>
          , will be published in I/ITSEC
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>R.</given-names>
            <surname>Gerhards</surname>
          </string-name>
          , The Syslog Protocol, http://tools.ietf.org/html/rfc5424,
          <string-name>
            <given-names>IETF</given-names>
            <surname>Std</surname>
          </string-name>
          . rfc5424,
          <year>March 2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>E.</given-names>
            <surname>Nemeth</surname>
          </string-name>
          , G. Snyder,
          <string-name>
            <given-names>S.</given-names>
            <surname>Seebass</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T.</given-names>
            <surname>Hein</surname>
          </string-name>
          ,
          <source>UNIX System Administration Handbook. Prentice Hall</source>
          ,
          <year>2000</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>I.</given-names>
            <surname>Horrocks</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. F.</given-names>
            <surname>Patel-Schneider</surname>
          </string-name>
          ,
          <string-name>
            <given-names>H.</given-names>
            <surname>Boley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Tabet</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Grosof</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Dean</surname>
          </string-name>
          , “
          <article-title>SWRL: A Semantic Web Rule Language Combining OWL</article-title>
          and RuleML,” http://www.w3.org/Submission/SWRL/, W3C Member Submission, May
          <year>2004</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [26]
          <string-name>
            <surname>Wireshark</surname>
          </string-name>
          , “Wireshark,” http://www.wireshark.org/,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>M.</given-names>
            <surname>Horridge</surname>
          </string-name>
          and
          <string-name>
            <given-names>S.</given-names>
            <surname>Bechhofer</surname>
          </string-name>
          ., “
          <article-title>The OWL API: A Java API for OWL Ontologies</article-title>
          .”
          <source>Semantic Web Journal</source>
          <volume>2</volume>
          (
          <issue>1</issue>
          ),
          <source>Special Issue on Semantic Web Tools and Systems</source>
          ,, pp.
          <fpage>11</fpage>
          -
          <lpage>21</lpage>
          ,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [28] “
          <article-title>Pellet: OWL 2 Reasoner for Java</article-title>
          ,” http://clarkparsia.com/pellet/,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>