Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
skip to main content
10.1145/3384217.3384222acmotherconferencesArticle/Chapter ViewAbstractPublication PageshotsosConference Proceedingsconference-collections
poster

Application of the armament cyber assessment framework: a security assessment methodology for military systems

Published: 21 September 2020 Publication History
  • Get Citation Alerts
  • Abstract

    As the Army modernizes, its weapon systems are becoming increasingly more cyber dependent. This increased connectivity provides incredible opportunities, but also introduces new risks. This paper introduces the Armament Cyber Assessment Framework (ACAF), a schema for creating security assessment workflows integrated into the design process. The goal of ACAF is to introduce a security oriented mindset into the solution prior to release, and to provide meaningful results at every level. This goal is accomplished through the study and incorporation of multiple industry leading frameworks into a uniquely iterative process. ACAF is implemented for testing via the Global Vulnerability Assessment and Penetration Platform (GVAPP). GVAPP works to provide automated vulnerability information during the armament design process. It offers meaningful risk calculus to armament designers without cyber security backgrounds to mitigate potential vulnerabilities prior to fielding the system. This work focuses on military applications, but is applicable to similar civilian platform technologies.

    References

    [1]
    2020. Cyber Kill Chain. https://www.lockheedmartin.com/content/dam/lockheed-martin/rms/documents/cyber/Gaining_the_Advantage_Cyber_Kill_Chain.pdf
    [2]
    0daysecurity.com. 2011. Penetration Testing Methodology - 0DAYsecurity.com. http://www.0daysecurity.com/pentest.html
    [3]
    Sean Barnum. 2012. Standardizing cyber threat intelligence information with the structured threat information expression (stix). Mitre Corporation 11 (2012), 1--22. http://stixproject.github.io/about/STIX_Whitepaper_v1.1.pdf
    [4]
    Rick Hayes. 2012. PTES Technical Guidelines - The Penetration Testing Execution Standard. http://www.pentest-standard.org/index.php/PTES_Technical_Guidelines
    [5]
    J. D. Mireles, J. Cho, and S. Xu. 2016. Extracting attack narratives from traffic datasets. In 2016 International Conference on Cyber Conflict (CyCon U.S.). 1--6.
    [6]
    U.S. Army Chief of Public Affairs. 2018. STAND-TO! http://www.army.mil/standto/2018-01-16
    [7]
    U.S. Department of the Army. 2016. FIELD ARTILLERY MANUAL CANNON GUNNERY. https://armypubs.army.mil/epubs/DR_pubs/DR_a/pdf/web/tc3_09x81.pdf
    [8]
    Blake Strom. 2019. Getting Started with ATT&CK: Adversary Emulation and Red Teaming. https://medium.com/mitre-attack/getting-started-with-attack-red-29f074ccf7e3
    [9]
    Cedric T. Wins. 2018. RDECOM's road map to modernizing the Army: Long-range precision fires. https://www.army.mil/article/211569/rdecoms_road_map_to_modernizing_the_army_long_range_precision_fires

    Recommendations

    Comments

    Information & Contributors

    Information

    Published In

    cover image ACM Other conferences
    HotSoS '20: Proceedings of the 7th Symposium on Hot Topics in the Science of Security
    September 2020
    189 pages
    ISBN:9781450375610
    DOI:10.1145/3384217
    Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

    Publisher

    Association for Computing Machinery

    New York, NY, United States

    Publication History

    Published: 21 September 2020

    Check for updates

    Author Tags

    1. military
    2. penetration test
    3. red team
    4. security assessment
    5. vulnerability scan

    Qualifiers

    • Poster

    Conference

    HotSoS '20
    HotSoS '20: Hot Topics in the Science of Security
    September 21 - 23, 2020
    Kansas, Lawrence

    Acceptance Rates

    Overall Acceptance Rate 34 of 60 submissions, 57%

    Contributors

    Other Metrics

    Bibliometrics & Citations

    Bibliometrics

    Article Metrics

    • 0
      Total Citations
    • 89
      Total Downloads
    • Downloads (Last 12 months)11
    • Downloads (Last 6 weeks)2

    Other Metrics

    Citations

    View Options

    Get Access

    Login options

    View options

    PDF

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader

    Media

    Figures

    Other

    Tables

    Share

    Share

    Share this Publication link

    Share on social media