Određivanje ulaganja i dobiti napadača u provođenje napada ; Determining investment and gain for attackers when performing cyber attack

Saved in:
Bibliographic Details
Title: Određivanje ulaganja i dobiti napadača u provođenje napada ; Determining investment and gain for attackers when performing cyber attack
Authors: Baričević, Ivor
Contributors: Groš, Stjepan
Publisher Information: Sveučilište u Zagrebu. Fakultet elektrotehnike i računarstva.
University of Zagreb. Faculty of Electrical Engineering and Computing.
Publication Year: 2023
Collection: Croatian Digital Theses Repository (National and University Library in Zagreb)
Subject Terms: napadačev trošak, napadačeva dobit, Cyber Conflict Simulator, napadački resursi, formula za izračun troška, skripta za izračun troška, attacker's cost, attacker's earnings, attacker's resources, cost calculation formula, cost calculation script, TEHNIČKE ZNANOSTI. Računarstvo, TECHNICAL SCIENCES. Computing
Description: Unatoč kontinuiranom rastu kibernetičkog kriminala, pouzdane procjene ekonomske štete napadačke strane su rijetke. Ovaj rad se bavi problemom izračunavanja ekonomske štete i ukupne dobiti napadačke organizacije. Za simulaciju napada se koristi alat Cyber Conflict Simulator (CCS), alat specifično dizajniran za modeliranje i simuliranje kibernetičkih napada. U radu se daje pregled jedne napadačke organizacije te svih resursa koje njeni članovi troše prilikom napada. Pomoću dostupne literature je procjenjen trošak tih resursa te je model ukomponiran u napad. Za potrebe procjene troška je kreirana i Python skripta koja pokriva troškove na mjestima na kojima CCS nema sposobnost odrediti trošak. Izabran je jedan scenarij napada te se prolaskom kroz njega pokušala odrediti šteta i dobit napadačke organizacije koristeći sam CCS alat i napravljenu skriptu. ; Despite the continuous growth of cybercrime, reliable estimates of the economic damage to the attacker side are rare. This paper deals with the problem of calculating the economic damage and profit of an attacker organization. The Cyber Conflict Simulator (CCS) tool, specifically designed for modeling and simulating cyber attacks, is used to simulate attacks. The thesis provides an overview of an attacker organization and all the resources it uses during an attack. The cost of these resources was estimated using available literature, and the model was incorporated into the attack. To estimate the cost, a Python script was created that covers costs in places where the CCS is unable to determine the cost. One attack scenario was chosen and an attempt was made to determine the damage and profit of the attacker organization using the CCS tool itself and the script made.
Document Type: bachelor thesis
File Description: application/pdf
Language: Croatian
Relation: https://zir.nsk.hr/islandora/object/fer:10790; https://urn.nsk.hr/urn:nbn:hr:168:449477; https://repozitorij.unizg.hr/islandora/object/fer:10790; https://repozitorij.unizg.hr/islandora/object/fer:10790/datastream/PDF
Availability: https://zir.nsk.hr/islandora/object/fer:10790
https://urn.nsk.hr/urn:nbn:hr:168:449477
https://repozitorij.unizg.hr/islandora/object/fer:10790
https://repozitorij.unizg.hr/islandora/object/fer:10790/datastream/PDF
Rights: http://rightsstatements.org/vocab/InC/1.0/ ; info:eu-repo/semantics/closedAccess
Accession Number: edsbas.2CE77DF8
Database: BASE
Description
Abstract:Unatoč kontinuiranom rastu kibernetičkog kriminala, pouzdane procjene ekonomske štete napadačke strane su rijetke. Ovaj rad se bavi problemom izračunavanja ekonomske štete i ukupne dobiti napadačke organizacije. Za simulaciju napada se koristi alat Cyber Conflict Simulator (CCS), alat specifično dizajniran za modeliranje i simuliranje kibernetičkih napada. U radu se daje pregled jedne napadačke organizacije te svih resursa koje njeni članovi troše prilikom napada. Pomoću dostupne literature je procjenjen trošak tih resursa te je model ukomponiran u napad. Za potrebe procjene troška je kreirana i Python skripta koja pokriva troškove na mjestima na kojima CCS nema sposobnost odrediti trošak. Izabran je jedan scenarij napada te se prolaskom kroz njega pokušala odrediti šteta i dobit napadačke organizacije koristeći sam CCS alat i napravljenu skriptu. ; Despite the continuous growth of cybercrime, reliable estimates of the economic damage to the attacker side are rare. This paper deals with the problem of calculating the economic damage and profit of an attacker organization. The Cyber Conflict Simulator (CCS) tool, specifically designed for modeling and simulating cyber attacks, is used to simulate attacks. The thesis provides an overview of an attacker organization and all the resources it uses during an attack. The cost of these resources was estimated using available literature, and the model was incorporated into the attack. To estimate the cost, a Python script was created that covers costs in places where the CCS is unable to determine the cost. One attack scenario was chosen and an attempt was made to determine the damage and profit of the attacker organization using the CCS tool itself and the script made.