Search papers, labs, and topics across Lattice.
This paper introduces a three-layer integrated probabilistic model for Cyber Situational Awareness (CSA) that enhances decision support in mission-critical cyber defense environments. By combining an attack-graph model, a Bayesian event model, and a state model, the framework effectively represents adversarial progression, defender uncertainty, and mission impact, allowing for informed defensive actions. The results demonstrate that the model maintains coherent relationships between attack progression and mission-risk prioritization, thereby improving operational resilience against cyber threats.
A unified framework that links adversarial progression to mission-risk prioritization, enhancing decision-making in cyber defense scenarios.
Cyber defense in mission-critical environments requires integrated approaches capable of representing adversarial progression, defender-side uncertainty, mission impact, and defensive decision support within a unified framework. In operational domains, defenders must continuously estimate the evolving security posture while preserving the continuity and integrity of mission-critical functions under incomplete and noisy observations. This paper presents a mission-oriented cyber-defense framework for Cyber Situational Awareness (CSA) and decision support based on a three-layer integrated probabilistic model and an executable simulation prototype. The model combines: (i) an attack-graph model that represents possible adversarial progression through mission-relevant assets, (ii) an event model that transforms observed telemetry into posterior defender beliefs through Bayesian inference, and (iii) a state model that abstracts the inferred posture into conflict states and mission-risk levels. These components are connected to a one-step defensive action rule that balances estimated residual mission risk and operational cost. The framework is instantiated in a NetLogo agent-based simulation of an operational environment structured across the Tactical Edge Zone (TEZ), Mission Operations Zone (MOZ), and Enterprise Support Zone (ESZ). The proposal is assessed through mathematical consistency analysis, local robustness assessment under telemetry perturbations, and representative simulation traces. Results indicate that the framework and its implementation preserve coherent relationships between attack progression, telemetry-driven uncertainty management, mission-impact assessment, and cost-aware defensive decision support guided by mission-risk prioritization.