d'Ambrosio, Nicola (2025) Boosting Cyber-Resilience in Networked Infrastructures via Risk Analysis and Active Deception Strategies. [Tesi di dottorato]
|
Documento PDF
NdAmbrosioThesis.pdf Visibile a [TBR] Utenti registrati Download (37MB) | Richiedi una copia |
| Tipologia del documento: | Tesi di dottorato |
|---|---|
| Lingua: | English |
| Titolo: | Boosting Cyber-Resilience in Networked Infrastructures via Risk Analysis and Active Deception Strategies |
| Autori: | Autore Email d'Ambrosio, Nicola nicola.dambrosio2@unina.it |
| Data: | 25 Febbraio 2025 |
| Numero di pagine: | 242 |
| Istituzione: | Università degli Studi di Napoli Federico II |
| Dipartimento: | Ingegneria Elettrica e delle Tecnologie dell'Informazione |
| Dottorato: | Information technology and electrical engineering |
| Ciclo di dottorato: | 37 |
| Coordinatore del Corso di dottorato: | nome email Russo, Stefano stefano.russo@unina.it |
| Tutor: | nome email Romano, Simon Pietro [non definito] |
| Data: | 25 Febbraio 2025 |
| Numero di pagine: | 242 |
| Parole chiave: | Moving Target Defense, Honeypots, STPA, Open System Architecture, Bayesian Attack Graphs, Digital Twins |
| Settori scientifico-disciplinari del MIUR: | Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni |
| Informazioni aggiuntive: | Sono un dottorando del XXXVII PNRR. Ho selezionato il XXXVI ciclo in quanto risulta essere l'ultimo disponibile all'interno della piattaforma |
| Depositato il: | 25 Feb 2025 19:13 |
| Ultima modifica: | 12 Ago 2026 05:38 |
| URI: | https://www.fedoa.unina.it/id/eprint/16737 |
Abstract
The frequency and sophistication of cyber-attacks have increased in recent years. Therefore, identifying major risks within the network infrastructure and designing effective cyber-defense strategies to mitigate these threats has become critical. In this context, we propose integrating risk analysis and active deception to improve the effectiveness of mitigating cyber threats affecting the network infrastructure. In detail, this methodology leverages STPA in conjunction with Attack Graphs to systematically determine high-impact cyber risks and discover pathways through which these risks could be triggered. To validate the proposed approach, we implemented it in two distinct environments: an avionic context employing a UAV testbed and a power distribution context using a MicroGrid testbed. Aligned with this research theme, we further investigate the integration of Digital Twins, Moving Target Defense (MTD), and STPA methodologies to detect malicious actions and isolate attackers within controlled environments. However, while the proposed methodology effectively evaluates actions that could result in unsafe conditions for people and assets, it cannot evaluate the impact and likelihood of insider threats (a limitation that traditional risk assessment approaches often fail to manage). To address this issue, we investigate the impact of insider threats using Bayesian threat graph networks. The results demonstrate that insider threats pose a significant risk to organizational security, underscoring the importance of incorporating them into comprehensive risk assessment frameworks and implementing targeted mitigation strategies. To further enhance cyber-defense capabilities, the SMASH framework was proposed to combine Honeypots and MTD as defensive deception techniques within a network infrastructure to mitigate risks posed by internal threats.
Downloads
Downloads per month over past year
Actions (login required)
![]() |
Modifica documento |


