Design and Validation of a Threat Model Based on Cyber Kill Chain Applied to Human Factors

Inés Hernández San Román, Marco Antonio Sotelo Monge, Víctor A. Villagra

Research output: Chapter in Book/Report/Conference proceedingPaper (Conference contribution)peer-review

Abstract

This document’s purpose is to study the impact of the cognitive domain in cybersecurity as a field, including its implications in cyberdefense and cyberspace, a domain that has gained traction in the last years due to the growing use of new technologies in everyday life. In addition, the investigation will focus on humans’ cognitive biases, how they influence decision making and how an hypothetical malicious individual could use these intrinsic vulnerabilities of the human mind in their favor to push misinformation campaigns, elaborate social engineering attacks or manipulate other people. Finally, a Cyber Kill Chain will be elaborated with the aim to illustrate the steps that the aforementioned attacker could take in order to achieve their goals successfully. The designed methodology will also be tested in a real-life scenario and will be validated by experts in the fields of cybersecurity and psychology.

Translated title of the contributionDiseño y Validación de un Modelo de Amenazas Basado en Cyber Kill Chain Aplicado a Factores Humanos
Original languageEnglish
Title of host publicationComputer Security. ESORICS 2022 International Workshops - CyberICPS 2022, SECPRE 2022, SPOSE 2022, CPS4CIP 2022, CDT and SECOMANE 2022, EIS 2022, and SecAssure 2022, Revised Selected Papers
EditorsSokratis Katsikas, Frédéric Cuppens, Christos Kalloniatis, John Mylopoulos, Frank Pallas, Jörg Pohle, M. Angela Sasse, Habtamu Abie, Silvio Ranise, Luca Verderame, Enrico Cambiaso, Jorge Maestre Vidal, Marco Antonio Sotelo Monge, Massimiliano Albanese, Basel Katt, Sandeep Pirbhulal, Ankur Shukla
PublisherSpringer Science and Business Media Deutschland GmbH
Pages482-499
Number of pages18
ISBN (Print)9783031254598
DOIs
StatePublished - 18 Feb 2023
Externally publishedYes
EventInternational Workshops which were held in conjunction with 27th European Symposium on Research in Computer Security, ESORICS 2022 - Copenhagen, Denmark
Duration: 26 Sep 202230 Sep 2022

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume13785 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Workshops which were held in conjunction with 27th European Symposium on Research in Computer Security, ESORICS 2022
Country/TerritoryDenmark
CityCopenhagen
Period26/09/2230/09/22

Keywords

  • Cognitive biases
  • Cognitive domain
  • Cyber Kill Chain
  • Cybersecurity
  • Cyberspace
  • Misinformation
  • Social engineering

Fingerprint

Dive into the research topics of 'Design and Validation of a Threat Model Based on Cyber Kill Chain Applied to Human Factors'. Together they form a unique fingerprint.

Cite this