EDBT 2026 Demo / reviewers in the wild / expert
Thomas D. Tarman
dblp:98/4318
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2024
0000-0001-7084-1225ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Validating an Emulation-Based Cybersecurity Model With a Physical TestbedabstractFor researchers studying cyber-physical system security, working with realistic datasets is essential. To produce the datasets, the existing methodology is to emulate the cyber network. A challenge is that the industrial control systems (ICS) network consists of not just computers and communication equipment, but also field devices that collect data and execute controls. These devices play a significant role in the operation and the security of the system. However, in comparison to the cyber network, the research reproducibility and realism of the cyber-physical system emulation and its data has received far less attention. This paper thus develops an approach to answer, ”How well can emulated devices replicate the behavior of physical intelligent electronics devices (IEDs) in a realistic cyber attack and defense environment?” To study this, we perform a comparison study based on an emulation experiment using theminimegatestbed environment that is entirely virtual and a hardware-in-the-loop experiment using the Resilient Energy Systems Lab (RESLab) cyber-physical testbed featuring real industrial controllers and communications devices. Results show that under different reconnaissance attack scenarios,RESLabgenerates realistic datasets that validate the emulation-based cybersecurity model inminimega. The approach is generalizable toward validating the realism of other types of ICS devices in security studies. Hao Huang 0006, Patrick Wlazlo, Abhijeet Sahu, Adele Walker, Ana Elisa P. Goulart, Katherine R. Davis 0001, Laura Painton Swiler, Thomas D. Tarman, Eric D. Vugrin |
IEEE Trans. Dependable Secur. Comput. | 8 |
| 2024 | Experimental Validation of a Command and Control Traffic Detection ModelabstractNetwork intrusion detection systems (NIDS) are commonly used to detect malware communications, including command-and-control (C2) traffic from botnets. NIDS performance assessments have been studied for decades, but mathematical modeling has rarely been used to explore NIDS performance. This paper details a mathematical model that describes a NIDS performing packet inspection and its detection of malware's C2 traffic. The paper further describes an emulation testbed and a set of cyber experiments that used the testbed to validate the model. These experiments included a commonly used NIDS (Snort) and traffic with contents from a pervasive malware (Emotet). Results are presented for two scenarios: a nominal scenario and a “stressed” scenario in which the NIDS cannot process all incoming packets. Model and experiment results match well, with model estimates mostly falling within 95$\%$confidence intervals on the experiment means. Model results were produced 70-3000 times faster than the experimental results. Consequently, the model's predictive capability could potentially be used to support decisions about NIDS configuration and effectiveness that require high confidence results, quantification of uncertainty, and exploration of large parameter spaces. Furthermore, the experiments provide an example for how emulation testbeds can be used to validate cyber models that include stochastic variability. Eric D. Vugrin, Seth Hanson, Jerry Cruz, Casey Glatter, Thomas D. Tarman, Ali Pinar |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Defender Policy Evaluation and Resource Allocation With MITRE ATT&CK Evaluations DataabstractProtecting against multi-step attacks of uncertain start times and duration forces the defenders into indefinite, always ongoing, resource-intensive response. To allocate resources effectively, the defender must analyze and respond to an uncertain stream of potentially undetected multiple multi-step attacks and take measures of attack and response intensity over time into account. Such response requires estimation of overall attack success metrics and evaluating effect of defender strategies and actions associated with specific attack steps on overall attack metrics. We present a novel game-theoretic approach GPLADD to attack metrics estimation and demonstrate it on attack data derived from MITRE’s ATT&CK Framework and other sources. In GPLADD, the time to complete attack steps is explicit; the attack dynamics emerges from attack graph and attacker-defender capabilities and strategies and therefore reflects “physics” of attacks. The time the attacker takes to complete an attack step is drawn from a probability distribution determined by attacker and defender strategies and capabilities. This makes time a physical constraint on attack success parameters and enables comparing different defender resource allocation strategies across different attacks. We solve for attack success metrics by approximating attacker-defender games as discrete-time Markov chains and show evaluation of return on detection investments associated with different attack steps. We apply GPLADD to MITRE’s APT3 data from ATT&CK Framework and show that there are substantial and un-intuitive differences in estimated real-world vendor performance against a simplified APT3 attack. We focus on metrics that reflect attack difficulty versus attacker ability to remain hidden in the system after gaining control. This enables practical defender optimization and resource allocation against multi-step attacks. Alexander V. Outkin, Patricia V. Schulz, Timothy Schulz, Thomas D. Tarman, Ali Pinar |
IEEE Trans. Dependable Secur. Comput. | 4 |