A Multi-criteria Approach to Improve the Cyber Security Visibility Through Breach Attack Simulations


Cyber threats are increasingly present in our daily lives and represent a great risk for companies. In this sense, organisations run breach attack simulations to generate an action plan and recommendations that must be followed. However, these action plans are the result of the tacit knowledge of specialists. Upon this issue, this research proposes a formal and automatic method to generate prioritized action plans to improve the visibility of the environment. The method proposed here is demonstrated through an experiment, in which the results were consistent and useful for the scenario in which it was tested.

Palavras-chave: multi-criteria, breach attack simulations, kill chain, MITRE attack


