d'Ambrosio, Nicola (2025) Boosting Cyber-Resilience in Networked Infrastructures via Risk Analysis and Active Deception Strategies. [Tesi di dottorato]

[thumbnail of NdAmbrosioThesis.pdf] Documento PDF
NdAmbrosioThesis.pdf
Visibile a [TBR] Utenti registrati

Download (37MB) | Richiedi una copia
Tipologia del documento: Tesi di dottorato
Lingua: English
Titolo: Boosting Cyber-Resilience in Networked Infrastructures via Risk Analysis and Active Deception Strategies
Autori:
Autore
Email
d'Ambrosio, Nicola
nicola.dambrosio2@unina.it
Data: 25 Febbraio 2025
Numero di pagine: 242
Istituzione: Università degli Studi di Napoli Federico II
Dipartimento: Ingegneria Elettrica e delle Tecnologie dell'Informazione
Dottorato: Information technology and electrical engineering
Ciclo di dottorato: 37
Coordinatore del Corso di dottorato:
nome
email
Russo, Stefano
stefano.russo@unina.it
Tutor:
nome
email
Romano, Simon Pietro
[non definito]
Data: 25 Febbraio 2025
Numero di pagine: 242
Parole chiave: Moving Target Defense, Honeypots, STPA, Open System Architecture, Bayesian Attack Graphs, Digital Twins
Settori scientifico-disciplinari del MIUR: Area 09 - Ingegneria industriale e dell'informazione > ING-INF/05 - Sistemi di elaborazione delle informazioni
Informazioni aggiuntive: Sono un dottorando del XXXVII PNRR. Ho selezionato il XXXVI ciclo in quanto risulta essere l'ultimo disponibile all'interno della piattaforma
Depositato il: 25 Feb 2025 19:13
Ultima modifica: 12 Ago 2026 05:38
URI: https://www.fedoa.unina.it/id/eprint/16737

Abstract

The frequency and sophistication of cyber-attacks have increased in recent years. Therefore, identifying major risks within the network infrastructure and designing effective cyber-defense strategies to mitigate these threats has become critical. In this context, we propose integrating risk analysis and active deception to improve the effectiveness of mitigating cyber threats affecting the network infrastructure. In detail, this methodology leverages STPA in conjunction with Attack Graphs to systematically determine high-impact cyber risks and discover pathways through which these risks could be triggered. To validate the proposed approach, we implemented it in two distinct environments: an avionic context employing a UAV testbed and a power distribution context using a MicroGrid testbed. Aligned with this research theme, we further investigate the integration of Digital Twins, Moving Target Defense (MTD), and STPA methodologies to detect malicious actions and isolate attackers within controlled environments. However, while the proposed methodology effectively evaluates actions that could result in unsafe conditions for people and assets, it cannot evaluate the impact and likelihood of insider threats (a limitation that traditional risk assessment approaches often fail to manage). To address this issue, we investigate the impact of insider threats using Bayesian threat graph networks. The results demonstrate that insider threats pose a significant risk to organizational security, underscoring the importance of incorporating them into comprehensive risk assessment frameworks and implementing targeted mitigation strategies. To further enhance cyber-defense capabilities, the SMASH framework was proposed to combine Honeypots and MTD as defensive deception techniques within a network infrastructure to mitigate risks posed by internal threats.

Downloads

Downloads per month over past year

Actions (login required)

Modifica documento Modifica documento