Advances in Cybersecurity Management
Book information
Description
This book concentrates on a wide range of advances related to IT cybersecurity management. The topics covered in this book include, among others, management techniques in security, IT risk management, the impact of technologies and techniques on security management, regulatory techniques and issues, surveillance technologies, security policies, security for protocol management, location management, GOS management, resource management, channel management, and mobility management. The authors also discuss digital contents copyright protection, system security management, network security management, security management in network equipment, storage area networks (SAN) management, information security management, government security policy, web penetration testing, security operations, and vulnerabilities management. The authors introduce the concepts, techniques, methods, approaches and trends needed by cybersecurity management specialists and educators for keeping current their cybersecurity management knowledge. Further, they provide a glimpse of future directions where cybersecurity management techniques, policies, applications, and theories are headed. The book is a rich collection of carefully selected and reviewed manuscripts written by diverse cybersecurity management experts in the listed fields and edited by prominent cybersecurity management researchers and specialists. Preface Acknowledgments Contents About the Editors Part I Network and Systems Security Management 1 Agent-Based Modeling of Entity Behavior in Cybersecurity 1.1 Introduction 1.2 Background 1.2.1 Modeling of Human Behavior 1.2.2 Modeling of System Behavior 1.2.3 Agent-Based Modeling (ABM) 1.3 Modeling and Simulation 1.3.1 Implementation 1.3.2 Simulation Results 1.3.2.1 Adversary Attack Sophistication 1.3.2.2 Trust Level 1.3.2.3 Quality or Level of Training 1.3.2.4 Quality of Cyber Defense 1.3.2.5 Comparison of Slow Growth Rates 1.3.2.6 Comparison of Fast Growth Rates 1.4 Cybersecurity Management Implications 1.5 Limitations of the Study 1.6 Conclusions and Future Directions References 2 A Secure Bio-Hash–Based Multiparty Mutual Authentication Protocol for Remote Health MonitoringApplications 2.1 Introduction 2.2 Related Work 2.3 The Proposed Scheme for Remote Health Monitoring Applications 2.3.1 Registration Phase of User 2.3.2 Login Phase of User 2.3.3 Authentication and Key Agreement Phase of User and MGW 2.3.4 Password Change Phase of User 2.3.5 System Set Up Phase of Medical Gateway 2.3.6 Registration Phase of Sensor with Medical Gateway 2.3.7 Registration Phase of Personal Device with Medical Gateway 2.3.8 Mutual Authentication Phase of Sensor, Personal Device and Medical Gateway 2.4 Security Analysis of Proposed Protocols 2.5 Formal Analysis Using Scyther Tool 2.6 Scyther Results and Interpretation 2.7 Conclusion References 3 Cybersecurity Attacks During COVID-19: An Analysis of the Behavior of the Human Factors and a Proposal of Hardening Strategies 3.1 Introduction 3.2 Cybersecurity Attacks During COVID-19 3.3 Analyzing Human Vulnerabilities for Fake News Using the Diamond Model 3.3.1 Adversary 3.3.2 Capability 3.3.3 Infrastructure 3.3.4 Victim 3.4 Strategies Against Fake News During COVID-19 3.5 Conclusions and Future Work References 4 Vehicle Network Security Metrics 4.1 Introduction 4.2 Vehicle Communication 4.2.1 Intra-vehicle Communication Protocols 4.2.2 Intervehicle Communication Protocols 4.3 Automotive Vehicle Network Security 4.3.1 Automotive Vehicle Threats and Vulnerabilities 4.3.2 Automotive Vehicle Security Attacks 4.3.3 Automotive Vehicle Attack Surfaces 4.4 Industry and Government Initiatives and Standards 4.5 Automotive Vehicle Security Metrics 4.5.1 Common Vulnerability Scoring System (CVSS) 4.5.2 Common Methodology for IT Security Evaluation (CEM) [49] 4.5.3 Security Metrics Visualization 4.6 Conclusion and Future Research Directions References 5 VizAttack: An Extensible Open-Source Visualization Framework for Cyberattacks 5.1 Introduction 5.2 Cyberattack Visualization Approaches 5.2.1 Cyberattack Maps and Graphs 5.2.2 Honeypot Data Visualization 5.2.3 Attack Visualization Challenges 5.3 VizAttack Design Principles 5.3.1 Design Objectives 5.3.2 High-Level Architectural Design 5.3.2.1 User Interface: Temporal Analysis 5.3.2.2 User Interface: Predefined Queries 5.3.2.3 User Interface: Customized Queries 5.3.2.4 User Interface: Profiling Attacks 5.4 VizAttack Implementation Details 5.4.1 VizAttack Prototype 5.4.2 Experimental Findings 5.4.3 Attack Postmortem Investigation 5.5 Conclusion References 6 Geographically Dispersed Supply Chains: A Strategy to Manage Cybersecurity in Industrial Networks Integration 6.1 Introduction 6.2 Challenges of Geographically-Dispersed Supply Chains 6.3 Critical Infrastructures 6.4 Vulnerabilities in Operational Technology Networks 6.5 International Cybersecurity Regulations and Standards 6.6 Proposed Cybersecurity Strategy for Industrial Networks 6.6.1 Perimeter and Security Controls Strategies 6.6.1.1 Electronic Security Perimeter 6.6.1.2 Data Flow in Segmented Networks 6.6.1.3 Network and Perimeter Monitoring 6.6.1.4 Network Access and Authentication 6.6.1.5 Network Perimeter Ports and Services 6.6.2 Host Security Controls Strategies 6.6.2.1 Asset Configuration 6.6.2.2 Ports and Services 6.6.2.3 Anti-Malware 6.6.2.4 Authentication 6.6.3 Security Monitoring Controls 6.6.3.1 Asset Configuration and Documentation 6.6.3.2 Monitoring 6.6.3.3 Authentication 6.7 Discussion 6.8 Final Considerations References 7 The Impact of Blockchain on Cybersecurity Management 7.1 Introduction 7.2 Anonymity and Privacy 7.3 Reputation Management 7.4 Identification and Integrity 7.5 Availability 7.6 Trust Management 7.7 Software Development Security 7.8 Conclusion References 8 A Framework for Enterprise Cybersecurity Risk Management 8.1 Introduction 8.1.1 Contributions of Our Chapter 8.1.2 Motivation for Business IT Alignment (BITA) 8.2 The Evolution of Cybersecurity RM 8.2.1 IT-Centric Approach 8.2.2 IS-Centric Approach 8.2.3 ERM-Centric Approach 8.2.4 Motivation for a New Approach 8.3 Evaluation of Existing Frameworks 8.3.1 NIST Framework 8.3.2 COSO Framework 8.3.3 COBIT Framework 8.3.4 ISO/IEC 31000 Framework 8.4 The Importance of BITA in Cybersecurity RM 8.4.1 BITA Capabilities 8.5 The CHARM Framework Development 8.5.1 The CHARM Framework 8.5.2 A Case Study Application of the CHARM Framework 8.6 Conclusions References 9 Biometrics for Enterprise Security Risk Mitigation 9.1 Introduction 9.2 Overview 9.2.1 Biometrics 9.2.2 The Process of Biometric Authentication and Accuracy Measures 9.2.3 Types of Biometrics 9.2.3.1 Fingerprints 9.2.3.2 Face Recognition 9.2.3.3 Iris Recognition 9.2.3.4 Other Biometrics 9.3 Related Works 9.3.1 Biometrics in Business Applications 9.3.1.1 Biometrics in Education 9.3.1.2 Biometrics for Mobile Device Security 9.3.1.3 Biometrics for the Healthcare Sector 9.3.1.4 Biometrics for the Financial Sector 9.3.2 Our Contribution 9.4 Biometrics in Enterprise Cybersecurity Risk Management 9.4.1 Biometrics in Multifactor Authentication Systems 9.5 The Technical, Financial, and Legal Challenges of Biometrics 9.5.1 Technical Challenges 9.5.1.1 Storage of Biometric Templates 9.5.1.2 Security Threats to a Biometric System 9.5.2 Legal Challenges 9.5.3 Financial and Usability Challenges 9.6 Case Studies of Enterprise Risk Mitigation via Biometrics During the COVID-19 Pandemic 9.6.1 The Impact of COVID-19 on Information Technology (IT) 9.6.1.1 Health Care 9.6.1.2 Academic 9.6.1.3 Financial 9.6.2 COVID-19 Impact on Information Security (IT) 9.6.3 Improving Security via Biometric Authentication 9.7 Conclusion 9.7.1 Future Research Opportunities References Part II Vulnerability Management 10 SQL Injection Attacks and Mitigation Strategies: The Latest Comprehension 10.1 Introduction 10.2 Background 10.2.1 Web Application Security 10.2.1.1 Understanding SQL Injection Attack 10.2.1.2 Logical Understanding of SQL Injection Attack 10.3 SQL Injection Attack Classification 10.3.1 In-Band SQL Injection Attacks 10.3.1.1 Union-Based SQL Injection Attack 10.3.1.2 Error-Based SQL Injection Attack 10.3.2 Inferential SQL Injection Attacks 10.3.2.1 Blind Boolean-Based SQL Injection Attack 10.3.2.2 Blind Time-Based SQL Injection Attack 10.3.3 Out-of-Band SQL Injection Attacks 10.3.4 Modern SQL Injection Attacks 10.4 SQL Injection Mitigation Strategies 10.4.1 OWASP [1] Suggested Mitigation Strategies 10.4.1.1 Principle of Least Privilege for Web-Application Access 10.4.1.2 Prepared Statements with Parameterized Queries 10.4.1.3 Stored Procedures 10.4.1.4 Query Whitelisting 10.4.1.5 Escaping All User-Supplied Input 10.4.2 SQL Injection Attack Mitigation Strategies: Research Outcomes 10.5 Conclusions References 11 Managing Cybersecurity Events Using Service-Level Agreements (SLAs) by Profiling the People Who Attack 11.1 Introduction 11.2 Prior Arts 11.2.1 Profiling Attackers from a Personal Perspective for SLA Provisioning and Network Management Objectives 11.3 Research Proposal 11.3.1 SLA Service Request 11.3.2 SLA Management 11.3.3 SLA and Data Management Interventions 11.4 Conclusions and Further Work References 12 Recent Techniques Supporting Vulnerabilities Management for Secure Online Apps 12.1 Introduction 12.2 SQL Injection 12.2.1 Introduction 12.2.2 Exploitation Techniques 12.2.2.1 In-Band SQL Injection 12.2.2.2 Inferential SQL Injection 12.2.2.3 Out-of-Band SQL Injection 12.2.3 Causes of Vulnerability 12.2.4 Protection Techniques 12.2.4.1 Input Validation 12.2.4.2 Data Sanitization 12.2.4.3 Use of Prepared Statements 12.2.4.4 Limitation of Database Permission 12.2.4.5 Using Encryption 12.3 Cross-Site Scripting 12.3.1 Introduction 12.3.2 Exploitation Techniques 12.3.2.1 Reflected Cross-Site Scripting 12.3.2.2 Stored Cross-Site Scripting 12.3.2.3 DOM-Based Cross-Site Scripting 12.3.3 Causes of Vulnerability 12.3.4 Protection Techniques 12.3.4.1 Data Validation 12.3.4.2 Data Sanitization 12.3.4.3 Escaping on Output 12.3.4.4 Use of Content Security Policy 12.4 Cross-Site Request Forgery 12.4.1 Introduction 12.4.2 Exploitation Techniques 12.4.2.1 HTTP Request with GET Method 12.4.2.2 HTTP Request with POST Method 12.4.3 Causes of Vulnerability 12.4.3.1 Session Cookie Handling Mechanism 12.4.3.2 HTML Tag 12.4.3.3 Browser's View Source Option 12.4.3.4 GET and POST Method 12.4.4 Protection Techniques 12.4.4.1 Checking HTTP Referer 12.4.4.2 Using Custom Header 12.4.4.3 Using Anti-CSRF Tokens 12.4.4.4 Using a Random Value for Each Form Field 12.4.4.5 Limiting the Lifetime of Authentication Cookies 12.5 Command Injection 12.5.1 Introduction 12.5.2 Exploitation Techniques 12.5.3 Causes of Vulnerability 12.5.4 Protection Techniques 12.6 File Inclusion 12.6.1 Introduction 12.6.2 Exploitation Techniques 12.6.2.1 Remote File Inclusion 12.6.2.2 Local File Inclusion 12.6.3 Causes of Vulnerability 12.6.4 Protection Techniques 12.7 Security Tools 12.8 Conclusion References 13 Information Technology Risk Management 13.1 Introduction to Risk Management 13.2 IT Risk Management Frameworks 13.2.1 NIST SP 800-30 Risk Framework 13.2.1.1 Risk Assessment 13.2.1.2 Risk Mitigation 13.2.1.3 Risk Evaluation and Assessment 13.2.2 Risk IT Framework by Information Systems Audit and Control Association (ISACA) 13.2.2.1 Risk Governance 13.2.2.2 Risk Evaluation 13.2.2.3 Risk Response 13.3 Threat Identification 13.4 Vulnerability and Weaknesses Identification 13.4.1 Vulnerability Sources 13.4.2 Security Requirements Checklist 13.4.3 System Security Testing 13.5 Risk Assessment 13.5.1 Likelihood and Impact Determination 13.5.2 Risk Determination 13.6 Risk Analysis 13.6.1 Quantitative Risk Analysis 13.6.2 Qualitative Risk Analysis 13.7 Risk Mitigation and Monitoring 13.8 Special Issues and Challenges in IT Risk Management 13.9 Emerging Trends and Research Directions 13.10 Summary References 14 From Lessons Learned to Improvements Implemented: Some Roles for Gaming in Cybersecurity Risk Management 14.1 Introduction 14.2 Background 14.2.1 Cybersecurity Risk Management 14.2.1.1 Managing, Assessing and Analyzing Risk 14.2.1.2 Quantifying Cybersecurity Risks 14.2.1.3 Cybersecurity Risk Management Frameworks 14.2.1.4 Other Tools and Techniques 14.2.2 Games and Their Purposes 14.2.2.1 Historical Perspective on Games 14.2.2.2 More About Wargames 14.2.2.3 Games with or About Cyber 14.2.3 Relevance of Games to Risk Management 14.3 Discussion 14.3.1 The Right Game for the Purpose 14.3.1.1 Learning Games 14.3.1.2 High-Level Cyber Games 14.3.1.3 Hands-on Tactical Exercises 14.3.1.4 Wargame Events 14.3.2 Cyber Wargame Examples 14.3.3 Qualities of Effective Cyber Games 14.3.4 Stepping into Cyber Wargaming 14.3.4.1 First Steps 14.3.4.2 Next Steps 14.3.4.3 Success Factors 14.3.4.4 Looking Back to Look Ahead 14.3.5 Potential Pitfalls 14.3.5.1 Design Uncertainty 14.3.5.2 Level of Abstraction 14.3.5.3 Value Proposition 14.3.5.4 Cybergaming as a Service 14.4 Conclusions 14.4.1 Summary 14.4.2 The Future for Cybersecurity Risk Management and Wargaming References 15 Applications of Social Network Analysis to Managing the Investigation of Suspicious Activities in Social MediaPlatforms 15.1 Introduction 15.1.1 Key Terms 15.2 Related Work 15.3 Use Case of Criminal Activities 15.3.1 Data Extraction from Twitter 15.4 SNA Metrics 15.5 Security Applications for SNA 15.5.1 Textual Analysis Applications 15.6 Counterintelligence 15.7 Crime Pattern Theory (CPT) 15.7.1 Graph Theory 15.7.2 Degree 15.7.3 Betweenness 15.7.4 Eigenvector 15.7.5 Closeness 15.8 Fraud Cyber Links 15.9 Online Social Network Attack: The Sybil Attack 15.10 Pattern Recognition 15.11 Online Social Network Trolling 15.11.1 Sockpuppet Account 15.11.1.1 Block Evasion 15.11.1.2 Ballot Stuffing 15.11.1.3 Strawman Sockpuppet 15.11.1.4 Meat Puppet 15.11.2 Catfishing 15.11.3 Sadfishing 15.11.4 Honey Trapping 15.12 Social Spam 15.12.1 Online Whispering Campaign 15.12.1.1 Votebot 15.12.1.2 Twitter Bomb 15.12.1.3 Search Engine Manipulation Effect 15.12.1.4 Crowd Manipulation 15.12.1.5 Gaslighting 15.13 Fake News Websites or Hoax News Websites 15.13.1 Mainstream Media 15.13.2 Messaging Spam 15.13.3 Internet Bot 15.13.4 Spamdexing 15.13.5 Spam Blogs 15.13.6 Forum Spam 15.13.7 Shitposting 15.14 Conclusion References 16 SIREN: A Fine Grained Approach to Develop Information Security Search Engine 16.1 Introduction 16.2 Fine Grained Approach for URL Identification 16.2.1 Approach 16.2.1.1 URL Extraction Process 16.2.1.2 Scoring 16.2.2 Results and Analysis 16.3 FACT: Fine Grained Assessment of CredibiliTy 16.3.1 Approach 16.3.1.1 Feature Identification 16.3.1.2 Surface Features 16.3.1.3 Content Features 16.3.1.4 Feature Value Extraction 16.3.1.5 Training Dataset Preparation 16.3.1.6 Data Normalization 16.3.1.7 Correlation 16.3.1.8 Automated Genre Classification 16.3.1.9 Scoring 16.3.2 Experiment 16.3.3 Results and Analysis 16.4 Conclusion and Future Work References 17 Dimensions of Cybersecurity Risk Management 17.1 Introduction 17.2 Systems of Interest 17.3 Characterizing and Modeling Risk 17.4 Autonomy, Trust, Identity Management, and Risk 17.4.1 Authentication and Identity Management 17.4.2 Trust and Deception 17.5 Intrusion Detection and Machine Learning 17.5.1 Role of Intrusion Detection 17.5.2 Machine Learning Approaches 17.5.3 Fuzzy Logic Intrusion Detection Systems 17.5.4 Dynamic Risk Monitoring 17.6 Conclusions References 18 The New Normal: Cybersecurity and Associated Drivers for a Post-COVID-19 Cloud 18.1 Introduction 18.2 Efficiency in the Cloud 18.3 Cybersecurity in the Cloud 18.3.1 Why Should We Care? 18.3.2 Considerations for Cybersecurity in the Cloud 18.4 Reliability in the Cloud 18.5 The Cost of Managing the Cloud 18.6 Research Concept Proposals 18.6.1 Reliability and Cost 18.6.2 Efficiency and Security 18.7 Conclusion References Part III Identity Management and Security Operations 19 Proven and Modern Approaches to Identity Management 19.1 Digital Identities 19.2 Principles of Identity Management 19.2.1 Identification and Enrolment of Identities 19.2.2 Authentication of Identities 19.2.2.1 Multi-factor Authentication 19.2.2.2 Step-Up Authentication 19.2.3 Authorization of Identities 19.2.4 Policies for Access Control 19.2.5 Accounting and Monitoring of Identities 19.2.6 Provisioning and Deprovisioning of Identities 19.3 Organization-Wide Identity and Access Management 19.3.1 Single Sign-On and Single Log-Out Mechanisms 19.3.2 Core Account Management Tasks 19.4 Federated Identity Management Across Organizations' Boundaries 19.4.1 Federations and Their Roles 19.4.2 Levels of Assurance for Confidence 19.4.3 Security Assertion Markup Language (SAML) 19.4.3.1 Elements of the Security Assertion Markup Language 19.4.3.2 Security of and Issues with Security Assertion Markup Language 19.4.4 The OAuth 2.0 Authorization Protocol 19.4.4.1 Elements of OAuth 2.0 19.4.4.2 Security of and Issues with OAuth 2.0 19.4.5 The OpenID Connect Authentication Layer for the OAuth 2.0 Protocol 19.4.5.1 Elements of OpenID Connect 19.4.5.2 Security of and Issues with OpenID Connect 19.4.6 Comparison of Security Assertion Markup Language, OAuth 2, and OpenID Connect 19.5 User-Centric and Self-Sovereign Identity Management 19.5.1 OAuth 2.0-Based User Managed Access 19.5.1.1 Elements of User-Managed Access 19.5.1.2 Security of and Issues with User-Managed Access 19.5.2 Self-Sovereign Identities 19.5.2.1 Elements of Self-Sovereign Identities 19.5.2.2 Security of and Issues with Self-Sovereign Identities 19.6 Summary References 20 A Hybrid Recommender for Cybersecurity Based on Rating Approach 20.1 Introduction 20.2 Theoretical Background 20.2.1 Cybersecurity Incident 20.2.2 Recommendation Systems 20.2.3 Types of Recommendation Systems 20.2.4 Recommenders Based on Collaborative Filtering 20.2.5 Knowledge-Based Recommenders 20.3 Related Works 20.4 Research Methodology 20.5 System Description 20.5.1 Logical Architecture 20.5.2 Physical Architecture of the Recommendation System 20.5.3 User Interface 20.6 Evaluation 20.7 Discussion 20.8 Conclusions References 21 An Introduction to Security Operations 21.1 Introduction to Security Operations 21.2 Generation of SO 21.3 Asset Management 21.4 Vulnerability Management 21.5 Threat Modeling 21.6 Risk Assessment, Analysis, and Mitigation in SO 21.6.1 Risk Identification 21.6.2 Risk Assessment 21.6.3 Risk Analysis 21.6.4 Risk Mitigation and Monitoring 21.6.5 Risk Review and Update 21.7 Incident Response Management 21.8 Special Issues and Challenges in SO 21.9 Related Emerging Technologies 21.10 Summary References Index
Similar books
Emerging Trends in Cybersecurity Applications
2022 · PDF
Quantum and Blockchain-based Next Generation Sustainable Computing (Contributions to Environmental Sciences & Innovative Business Technology)
2024 · RAR
Quantum and Blockchain-based Next Generation Sustainable Computing (Contributions to Environmental Sciences & Innovative Business Technology)
2024 · EPUB
Quantum and Blockchain-based Next Generation Sustainable Computing (Contributions to Environmental Sciences & Innovative Business Technology)
2024 · PDF
Proceedings of the 2023 International Conference on Advances in Computing Research (ACR’23) (Lecture Notes in Networks and Systems, 700)
2023 · PDF
Proceedings of the ICR’22 International Conference on Innovations in Computing Research (Advances in Intelligent Systems and Computing, 1431)
2022 · PDF
Proceedings of the Second International Conference on Advances in Computing Research (ACR’24) (Lecture Notes in Networks and Systems, 956)
2024 · PDF
Current and Future Trends in Health and Medical Informatics (Studies in Computational Intelligence, 1112)
2023 · PDF