IDEAS home Printed from https://ideas.repec.org/a/igg/jisp00/v17y2023i1p1-23.html
   My bibliography  Save this article

A System Dynamics Approach to Evaluate Advanced Persistent Threat Vectors

Author

Listed:
  • Mathew Nicho

    (Rabdan Academy, UAE)

  • Christopher D. McDermott

    (Robert Gordon University, UK)

  • Hussein Fakhry

    (Zayed University, UAE)

  • Shini Girija

    (Zayed University, UAE)

Abstract

Cyber-attacks targeting high-profile entities are focused, persistent, and employ common vectors with varying levels of sophistication to exploit social-technical vulnerabilities. Advanced persistent threats (APTs) deploy zero-day malware against such targets to gain entry through multiple security layers, exploiting the dynamic interplay of vulnerabilities in the target network. System dynamics (SD) offers an alternative approach to analyze non-linear, complex, and dynamic social-technical systems. This research applied SD to three high-profile APT attacks - Equifax, Carphone, and Zomato - to identify and simulate socio-technical variables leading to breaches. By modeling APTs using SD, managers can evaluate threats, predict attacks, and reduce damage by mitigating specific socio-technical cues. This study provides valuable insights into the dynamics of cyber threats, making it the first to apply SD to APTs.

Suggested Citation

  • Mathew Nicho & Christopher D. McDermott & Hussein Fakhry & Shini Girija, 2023. "A System Dynamics Approach to Evaluate Advanced Persistent Threat Vectors," International Journal of Information Security and Privacy (IJISP), IGI Global, vol. 17(1), pages 1-23, January.
  • Handle: RePEc:igg:jisp00:v:17:y:2023:i:1:p:1-23
    as

    Download full text from publisher

    File URL: http://services.igi-global.com/resolvedoi/resolve.aspx?doi=10.4018/IJISP.324064
    Download Restriction: no
    ---><---

    References listed on IDEAS

    as
    1. Mohd Nor Akmal Khalid & Amjed Ahmed Al-Kadhimi & Manmeet Mahinderjit Singh, 2023. "Recent Developments in Game-Theory Approaches for the Detection and Defense against Advanced Persistent Threats (APTs): A Systematic Review," Mathematics, MDPI, vol. 11(6), pages 1-34, March.
    2. Amitava Dutta & Rahul Roy, 2008. "Dynamics of organizational information security," System Dynamics Review, System Dynamics Society, vol. 24(3), pages 349-375, September.
    Full references (including those not matched with items on IDEAS)

    Most related items

    These are the items that most often cite the same works as this one and are cited by the same works as this one.
    1. Stanislava Mildeová & Martin Dalihod, 2017. "Systems Approach to Scientific Investigation in Informatics [Systémový přístup k vědeckému zkoumání v informatice]," Acta Informatica Pragensia, Prague University of Economics and Business, vol. 2017(1), pages 60-69.

    More about this item

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:igg:jisp00:v:17:y:2023:i:1:p:1-23. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    If CitEc recognized a bibliographic reference but did not link an item in RePEc to it, you can help with this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Journal Editor (email available below). General contact details of provider: https://www.igi-global.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.