A Method for Assigning Probability Distributions in Attack Simulation Languages

Wenjun Xiong, Simon Hacks, Robert Lagerström


Cyber attacks on IT and OT systems can have severe consequences for individuals and organizations, from water or energy distribution systems to online banking services. To respond to these threats, attack simulations can be used to assess the cyber security of systems to foster a higher degree of resilience against cyber attacks; the steps taken by an attacker to compromise sensitive system assets can be traced, and a time estimate can be computed from the initial step to the compromise of assets of interest.

Previously, the Meta Attack Language (MAL) was introduced as a framework to develop security-oriented domain-specific languages. It allows attack simulations on modeled systems and analyzes weaknesses related to known attacks. To produce more realistic simulation results, probability distributions can be assigned to attack steps and defenses to describe the efforts required for attackers to exploit certain attack steps. However, research on assessing such probability distributions is scarce, and we often rely on security experts to model attackers’ efforts. To address this gap, we propose a method to assign probability distributions to the attack steps and defenses of MAL-based languages. We demonstrate the proposed method by assigning probability distributions to a MAL-based language. Finally, the resulting language is evaluated by modeling and simulating a known cyber attack.


Attack Simulations; Threat Modeling; Domain-Specific Language; Cyber Security; Information Collection

Full Text:


DOI: 10.7250/csimq.2021-26.04


  • There are currently no refbacks.

Copyright (c) 2021 Wenjun Xiong, Simon Hacks, Robert Lagerström

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.