Cardiff University | Prifysgol Caerdydd ORCA
Online Research @ Cardiff 
WelshClear Cookie - decide language by browser settings

Consistent and compatible modelling of cyber intrusions and incident response demonstrated in the context of malware attacks on critical infrastructure

Maynard, Peter, Cherdantseva, Yulia ORCID: https://orcid.org/0000-0002-3527-1121, Shaked, Avi and Burnap, Pete ORCID: https://orcid.org/0000-0003-0396-633X 2026. Consistent and compatible modelling of cyber intrusions and incident response demonstrated in the context of malware attacks on critical infrastructure. Journal of Cybersecurity and Privacy 6 (4) , 109. 10.3390/jcp6040109

[thumbnail of jcp-06-00109.pdf] PDF - Published Version
Available under License Creative Commons Attribution.

Download (11MB)

Abstract

Cyber Security Incident Response (IR) playbooks are used to capture the steps required to recover from a cyber intrusion. Intrusion modelling focuses on a specific potential cyber intrusion and is used to identify where and what countermeasures are needed. The resulting intrusion models are expected to be used in IR, ideally by feeding IR playbook designs. However, IR playbooks and intrusion models are created in isolation and at varying stages of the system’s lifecycle, and there is no systematic approach that allows for their integration. In this article, we present a new approach to integrate intrusion models and IR models by translating intrusion models into a form compatible with IR models. We take nine critical national infrastructure intrusion models—expressed using Sequential AND Attack Trees—and transform them into models of the same format as IR playbooks, using a newly devised, automated conversion application. We use the Security Modelling Framework for modelling intrusions and playbooks, and for demonstrating the feasibility of the better integration between them based on operational impact. This results in enhanced intrusion models that are contextualised with respect to operations and, accordingly, can offer tighter coupling with IR playbooks. The main contributions of this paper are (a) a novel way of representing attack trees, (b) a new tool for automatically converting Sequential AND attack trees into models compatible with playbooks, and (c) examples of nine real-world intrusion models.

Item Type: Article
Date Type: Publication
Status: Published
Schools: Schools > Computer Science & Informatics
Publisher: MDPI
Date of First Compliant Deposit: 1 July 2026
Date of Acceptance: 25 June 2026
Last Modified: 01 Jul 2026 14:15
URI: https://orca.cardiff.ac.uk/id/eprint/187863

Actions (repository staff only)

Edit Item Edit Item

Downloads

Downloads per month over past year

View more statistics