Ferda Özdemir Sönmez

dblp:242/1719 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2022
0000-0002-0908-2554ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2022 Attack Dynamics: An Automatic Attack Graph Generation Framework Based on System Topology, CAPEC, CWE, and CVE Databases
abstract
Through a built-in security analysis feature based on metadata, this article provides a novel framework that starts with a scenario input and produces a collection of visualizations based on Common Attack Pattern Enumeration and Classification (CAPEC) and Common Weakness Enumeration (CWE) Standards. It immediately links enterprise mitigations from MITRE ATT&CK framework to the security flaws it discovered. It’s also integrated with a third-party optimization tool targeted at cutting security costs for businesses, which it can perform in real-time or later using JSON output in the preferred format, depending on the execution mode. All of these stages are conducted without human intervention. Adaptive metadata with a variety of rules for capturing different sorts of known or prospective attack types allows for the production of attack graphs. It can be used as a quick and practical what-if analysis tool to detect potential intrusions for a variety of network configuration setups and assigned access privileges. As a threat modeler, it is suitable for both novice and expert users. Due to the easy input scheme and human-readable outputs, it can also be utilized as an educational tool.
Ferda Özdemir Sönmez, Chris Hankin, Pasquale Malacaria
Comput. Secur.1
2022 Decision support for healthcare cyber security
abstract
The pandemic has demonstrated that healthcare systems are prime targets for attackers. Finding an optimal security control set is a constant challenge for health organizations, where cost is a major consideration. The purpose of this paper is to demonstrate a healthcare cost optimization system as well as a case study based on two IT setup configurations that have been evaluated by medical experts as well as IT experts. These configurations would aid in conveying the complexity of the decision parameters and demonstrating how CySecTool handles this difficulty. In the study, 64 different security controls were linked to 70 vulnerabilities that could occur at any level of a hospital system dealing with both internal and external attacks/risks. The study also includes a novel visualization scheme that allows for the observation of vulnerabilities and also their subcategories based on Microsoft's STRIDE categorization.
Ferda Özdemir Sönmez, Chris Hankin, Pasquale Malacaria
Comput. Secur.1
2021 A Decision Support System for Optimal Selection of Enterprise Information Security Preventative Actions
abstract
Types and complexity of information security related vulnerabilities are growing rapidly and present numerous challenges to the enterprises. One of the key challenges is to identify the optimal set of precautions with limited budget. Despite the fact that majority of enterprises have a budget constraint for installing and maintaining the protection systems, the majority of the previous work only focus on prioritization of security targets and do not consider the preventative actions and budget constraints. This article presents a decision support system (DSS) based on analytical hierarchical process and mixed integer programming techniques for optimal selection of enterprise information security preventative actions. The proposed approach enables maximizing the amount of risk prevented for a fixed amount of budget by identifying the optimal set of precautions. The new DSS also assists enterprise decision-makers in determining the minimum enterprise information security budget for a given level of risk. The main contribution of the paper is that it provides a risk management method to identify a multi-level threat model and the corresponding optimal combination of preventative actions for an enterprise while considering the budget constraints. The treemap information visualization technique is also integrated into the proposed method to improve information security related management decisions.
Ferda Özdemir Sönmez, Banu Gunel
IEEE Trans. Netw. Serv. Manag.1