Comparing models of offensive cyber operations

The work

AuthorsTim Grant; Ivan Burke; Renier Van Heerden
Editors
Typeincollection
Year2015
Citekeygrant2015comparing

Where it appeared

Published inLeading Issues in Cyber Warfare and Security: Cyber Warfare and Security
Volume2
Pages35

Abstract

Cyber operations denote the response of governments and organisations to cyber crime, terrorism, and warfare. To date, cyber operations have been primarily defensive, with the attackers seemingly having the initiative. Over the past three years, several nations (e.g. USA, UK, France, The Netherlands) and NATO have published cyber security strategies emphasising national and international collaboration. Many strategies call for the establishment of a Cyber Security Operations Centre, as well as for a better understanding of attacks. In the scientific literature, Lin (2009) and Denning and Denning (2010) have argued that offensive cyber operations deserve a more open discussion than they have received to date. Research into cyber attacks would improve the scientific understanding of how attackers work, why they choose particular targets, and what tools and technologies they employ. This improved understanding could then be used to implement better defences. Moreover, research would enable governments and other organizations to take offensive action where justified against adversaries, whether these be criminals, terrorists, or enemies. This could include responding to an (impending) attack by counter-attacking or by proactively neutralizing the source of an impending attack. A good starting point to improving understanding would be to model the offensive cyber operations process. The purpose of this paper is to find, formalise, and compare models of the offensive cyber operations process available in the open scientific literature. Seven models were sufficiently well described for formalisation using Structured Analysis and Design Technique (SADT) notation. Finally, a canonical model has been constructed by rational reconstruction. Although the model has not yet been tested, it has been reviewed by subject matter experts. The paper describes the search methodology, the SADT analysis, the shortcomings of each model, rational reconstruction, and the canonical model. Further work will include elaborating the canonical model to identify the resources needed to set up a Cyber Security Operations Centre with offensive capabilities and to cross-compare the model with the literature on attack ontologies.

A copy is held

pdf, 2.1 MB. Not published — it may be under copyright. The facts and links here are.

How it got here

How it got hereimport via bibtex
Added2026-08-04 00:00 UTC
Approved bya person 2026-08-16 16:11 UTC

Cite it as

@incollection{grant2015comparing,
  title        = {Comparing models of offensive cyber operations},
  author       = {Tim Grant and Ivan Burke and Renier Van Heerden},
  year         = {2015},
  booktitle    = {Leading Issues in Cyber Warfare and Security: Cyber Warfare and Security},
  volume       = {2},
  pages        = {35},
}

This record lives at https://refs.drheap.org/grant2015comparing/ and will keep doing so.