ENGLISH

Theoretical Cybersecurity: Principles and Advanced Concepts

Book information

Publisher
Apress
Year
2022
ISBN
9781484283004, 9781484282991
Language
english
Format
PDF
Filesize
4 MB (4671148 bytes)
Pages
229\224
Time added
2022-07-13 15:21:21

Description

There is a distinct lack of theoretical innovation in the cybersecurity industry. This is not to say that innovation is lacking, as new technologies, services, and solutions (as well as buzzwords) are emerging every day. This book will be the first cybersecurity text aimed at encouraging abstract and intellectual exploration of cybersecurity as a practice from the philosophical and speculative perspective. Technological innovation is certainly necessary, as it furthers the purveying of goods and services for cybersecurity producers in addition to securing the attack surface of cybersecurity consumers where able. The issue is that the industry, sector, and even academia are largely technologically focused. There is not enough work done to further the trade―the craft of cybersecurity. This book frames the cause of this and other issues, and what can be done about them. Potential methods and directions are outlined regarding how the industry can evolve to embrace theoretical cybersecurity innovation as it pertains to the art, as much as to the science. To do this, a taxonomy of the cybersecurity body of work is laid out to identify how the influences of the industry’s past and present constrain future innovation. Then, cost-benefit analysis and right-sizing of cybersecurity roles and responsibilities―as well as defensible experimentation concepts―are presented as the foundation for moving beyond some of those constraining factors that limit theoretical cybersecurity innovation. Lastly, examples and case studies demonstrate future-oriented topics for cybersecurity theorization such as game theory, infinite-minded methodologies, and strategic cybersecurity implementations. What you’ll learn The current state of the cybersecurity sector and how it constrains theoretical innovation How to understand attacker and defender cost benefit The detect, prevent, and accept paradigm How to build your own cybersecurity box Supporting cybersecurity innovation through defensible experimentation How to implement strategic cybersecurity Infinite vs finite game play in cybersecurity Who This Book Is For This book is for both practitioners of cybersecurity and those who are required to, or choose to, employ such services, technology, or capabilities. Table of Contents About the Authors About the Technical Reviewer Disclaimer Chapter 1: Introduction What Is It? What Is It Not? Case Study Observation Theoretical Concept Experiment Results Conclusions Case Study Analysis Cyber Sniff Test Observation and Theory Experimentation Implications for Implementation Summary Chapter 2: A Cyber Taxonomy A Case of Identity Crisis Cybersecurity Analyst Cybersecurity Engineer Comparison Taxonomy of the Profession Our Taxonomy Types of Cybersecurity Detect Investigate Create Operate Architect Audit Analyze Emulate Functional Subsets Data Functions System Functions Framework Functions Antagonist Functions Actional Subsets Reactive Proactive Analogy Detective Investigative Create Operate Architects Auditors Intelligence Creators Adversary Emulation So, What’s the Point? The Tradecraft Concepts Summary Chapter 3: Cost Benefit Warning Real Motivation Examples Industry Wide Example: Retention Defensive Cybersecurity Example: Metrics Offensive Cybersecurity Example: Reporting Understanding Cost Benefit Perspectives Cost Benefit to the Target Cost Benefit to the Attacker Summary Understanding Cost Benefit Implications Risk and Work Are Never Destroyed (ish) Poor Evaluation of Cost Benefit Implications Good Cost Benefit Implications Evaluation A Litmus Test for Cost Benefit Summary Chapter 4: Roles and Responsibilities Responsibilities to Shed Case Study 1 What Happened Why It Is Inappropriate Who Is Responsible Case Study 2 What Happened Why It Is Inappropriate Who Is Responsible Case Study 3 What Happened Why It Is Inappropriate Who Is Responsible Responsibilities to Embrace Example: Be Your Own Enemy Learning to Leverage the Non-Cyber Example 1 Example 2 Building the Right Size Box Step 1: Know Thy Cyber-Self Step 2: Prevent What Is Known Step 3: Know Thy Strategic Self Step 4: Leverage Non-Cyber Step 5: Calibrate and Implement Step 6: Reassessment Summary Chapter 5: Experimentation Identifying Requirements for Defensible Evaluation Controlled and Realistic Environment Defensible Configuration Defensible Operation Defensible Emulation of a Motivated and Sophisticated Attacker Measurable Results and Metrics Evaluation Mediums Real Network and Operators with Real Attackers Real Network and Operators with Simulated Attackers Lab Network with Real Attackers Lab Network with Simulated Attacker Evaluation Mediums Summary Experimentation Example Experiment Design Target Determination to Support Realistic Network Experiment Summary Lab Design Lab Network Operating Systems Experiment Metrics Personnel Requirements Control Network and Related Documentation Created Network Audited for Realism and Functionality Control Network Cloned Red Team Assessment Audit of Red Team Recommendations by Red Team Auditor Audit of Red Team Recommendations by Systems Administration Auditor Audit of CAPTR Team Recommendations by Systems Administration Auditor Verification of CAPTR Teamer Recommended Changes Addressing Defensibility Requirements Summary Chapter 6: Strategic Cybersecurity What It Is Not A Move Toward Resiliency On Cybersecurity Insurance Counter-APT Red Teaming Outcome-Oriented Scoping Worst-Case Risk Assessment Survivability CAPTR Team Critical Initialization Perspective Reverse Red Teaming Reverse Pivot Chaining Local Assessment Analysis of Local Intelligence Reverse Pivoting CAPTR Reporting Web of Reverse Risk Relationships Math Is Hard A Discussion on CAPTR Reporting Cost Benefit Application of Strategic Cybersecurity The Classic Approach The Strategic Approach Summary Chapter 7: Strategic Defensive Security Architecture The Classic Approach The Strategic Approach Monitor and Detect The Classic Approach The Strategic Approach Investigate The Classic Approach The Strategic Approach Frameworks Auditing Theoretical Case Studies The Architecture of Accountable Sectors Military Resiliency Chapter 8: Infinite Cybersecurity The Infinite Game The Lesson Infinite Cybersecurity Weaknesses and a Strength Time Money Information and Access Finite Battles in an Infinite War Applying the Theory Adversary as a Service (AaaS) Attacking the Curve Cost Benefit Refined Summary Chapter 9: Cybersecurity and Game Theory The Infinite Cybersecurity Game Players in the Cybersecurity Game States in the Cybersecurity Game Actions in the Cybersecurity Game Payoffs in the Cybersecurity Game Knowledge and Beliefs in the Cybersecurity Game Modeling the Cybersecurity Game Analysis of the Cybersecurity Game Subgame Analysis Chapter 10: Game Theory Case Study: Ransomware Introduction Payoff and Recovery Reputation Payoff Negotiation Ransom Response, Mitigation, and Retaliation Activation and Demand Deployment Selection Capability Development Deployment Activation, Demand, Mitigation, Retaliation, Recovery Response, Negotiation, Payoff Attacker Types Target Selection Summary Index

Similar books

Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36

2010 · PDF

THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.

1858 · PDF

Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.

2022 · PDF

The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians

1809 · PDF