Next Article in Journal
SQnet: An Enhanced Multi-Objective Detection Algorithm in Subaquatic Environments
Previous Article in Journal
Modelling Analysis of Channel Assembling in CRNs Based on Priority Scheduling Strategy with Reserved Queue
Previous Article in Special Issue
Clustering Network Traffic Using Semi-Supervised Learning
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Article

Improving Attack Graph Visual Syntax Configurations

by
Askhat Sherzhanov
1,
Hany F. Atlam
1,*,
Muhammad Ajmal Azad
2 and
Harjinder Singh Lallie
1
1
Cyber Security Centre, WMG, University of Warwick, Coventry CV4 7AL, UK
2
School of Computing, Birmingham City University, SteamHouse, Belmont Row, Birmingham B4 7RQ, UK
*
Author to whom correspondence should be addressed.
Electronics 2024, 13(15), 3052; https://doi.org/10.3390/electronics13153052
Submission received: 21 June 2024 / Revised: 26 July 2024 / Accepted: 29 July 2024 / Published: 1 August 2024
(This article belongs to the Special Issue Network Security and Cryptography Applications)

Abstract

As technology advances and cyber threats become increasingly sophisticated, the task of recognising and understanding malicious activities becomes more complex. This persistent issue is widely acknowledged and extensively documented within the cybersecurity community. Attack modelling techniques (AMTs), such as attack graphs, have emerged as valuable tools in aiding cyberattack perception. These visualisation tools offer crucial insights into the complex relationships between various components within a system or network, shedding light on potential attack paths and vulnerabilities. This paper proposes an attack graph visual syntax method to improve cyberattack perception among experts and non-experts. The proposed approach was developed to streamline complexity and enhance clarity, thus augmenting the interpretability for users by enhancing visual structural components, such as hue, chromaticity, and line parameters. The proposed attack graph (pag) was empirically evaluated against the adapted attack graph (aag) presented in the literature. The empirical evaluation (n = 83) was conducted through a 3 × 2 × 2 factorial design and two-way analysis of variance (ANOVA) with repeated measures. The participants were classified according to their respective background cohorts into expert and non-expert (expert n = 37, non-expert n = 46) and then grouped into two groups: proposed attack graph (pag) and adapted attack graph (aag) (pag n = 41, aag n = 42). The empirical results demonstrated that while the proposed attack graph (pag) implemented various visual modifications such as brighter hues, denser line structures, and varied shapes, these enhancements did not significantly improve the perception of cyberattacks among individuals who lack expertise in the field, including corporate executives. Moreover, the use of variables such as colour, tone, and line width/density/structure did not help objects in the graph be distinguished more effectively. This paper provides significant insights into the impact of visual enhancements on cyberattack perception, highlighting that visual enhancements alone may not be sufficient to improve cyberattack perception for individuals lacking expertise in the field.
Keywords: attack graph; visual syntax; cyberattack; cybersecurity; attack modelling attack graph; visual syntax; cyberattack; cybersecurity; attack modelling

Share and Cite

MDPI and ACS Style

Sherzhanov, A.; Atlam, H.F.; Azad, M.A.; Lallie, H.S. Improving Attack Graph Visual Syntax Configurations. Electronics 2024, 13, 3052. https://doi.org/10.3390/electronics13153052

AMA Style

Sherzhanov A, Atlam HF, Azad MA, Lallie HS. Improving Attack Graph Visual Syntax Configurations. Electronics. 2024; 13(15):3052. https://doi.org/10.3390/electronics13153052

Chicago/Turabian Style

Sherzhanov, Askhat, Hany F. Atlam, Muhammad Ajmal Azad, and Harjinder Singh Lallie. 2024. "Improving Attack Graph Visual Syntax Configurations" Electronics 13, no. 15: 3052. https://doi.org/10.3390/electronics13153052

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop