Date of Award

2017

Document Type

Thesis

Degree Name

Master of Science (MS)

Department

Computer Science : Modeling and Simulation

Committee Chair

Mikel D. Petty

Committee Member

Eric Imsand

Committee Member

Harry S. Delugach

Subject(s)

Petri nets, System analysis, Penetration testing (Computer security), Computer networks--Security measures--Testing

Abstract

As part of a team project modeling computer system vulnerabilities and cyberattacks, this research focused on Petri net models and validation methods for them. First, the chosen target, Metasploitable, was scanned for vulnerabilities, which were matched to Common Attack Pattern Enumeration and Classification (CAPEC) entries. For a preliminary validation, the models were compared with the entries. Then a dynamic validation was applied to two models of CAPEC entries and to one model of a known backdoor, Ingreslock. Three experimental cyberattacks were compared with their respective models, giving partial validation. The results of the comparison show that this dynamic method was only sufficient to validate a specific sequence of each attack. Formal analysis of Petri net properties proved to be more suited to verification of the model, rather than validation.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.