Creating a Digital Twin of an Insider Threat Detection Enterprise Using Model-Based Systems Engineering

被引:9
作者
Lee, James [1 ]
Alghamdi, Ahmad [1 ]
Zaidi, Abbas K. [1 ]
机构
[1] George Mason Univ, Dept Syst Engn & Operat Res, Fairfax, VA 22030 USA
来源
SYSCON 2022: THE 16TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON) | 2022年
关键词
Digital Twin; MBSE; Insider Threat; System Engineering; ONTOLOGY;
D O I
10.1109/SysCon53536.2022.9773890
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Inference Enterprise Modeling (IEM) is a methodology developed to address test and evaluation limitations that insider threat detection enterprises face due to a lack of ground truth and/or missing data. IEM uses a collection of statistical, data processing, analysis, and machine learning techniques to estimate and forecast the performance of these enterprises. As part of developing the IEM method, models satisfying various detection system evaluation requirements were created. In this work, we extend IEM as a digital twin generation technique by representing modeled processes as executable UML Activity Diagrams and tracing solution processes to problem requirements using ontologies. Using the proposed framework, we can rapidly prototype a digital twin of a detection system that can also be imported and executed in systems engineering simulation software tools such as Cameo Enterprise Architecture Simulation Toolkit. Cyber security and threat detection is a continuous process that requires regular maintenance and testing throughout its lifecycle, but there often exists access issues for sensitive and private data and proprietary detection model details to perform adequate test and evaluation activities in the live production environment. To solve this issue, organizations can use a digital twin technique to create a real-time virtual counterpart of the physical system. We describe a method for creating digital twins of live and/or hypothetical insider threat detection enterprises for the purpose of performing test and evaluation activities on continuous monitoring systems that are sensitive to disruptions. In this work, we use UML Activity Diagrams to leverage the integrated simulation capabilities of Model-Based Systems Engineering (MBSE).
引用
收藏
页数:7
相关论文
共 25 条
[11]  
Graves H., 2013, MBSE ONTOLOGY MBSE W
[12]  
Happel H-J, 2006, Proc. of Workshop on Sematic Web Enabled Software Engineering"(SWESE) on the ISWC, P5
[13]   The Gene Ontology (GO) database and informatics resource [J].
Harris, MA ;
Clark, J ;
Ireland, A ;
Lomax, J ;
Ashburner, M ;
Foulger, R ;
Eilbeck, K ;
Lewis, S ;
Marshall, B ;
Mungall, C ;
Richter, J ;
Rubin, GM ;
Blake, JA ;
Bult, C ;
Dolan, M ;
Drabkin, H ;
Eppig, JT ;
Hill, DP ;
Ni, L ;
Ringwald, M ;
Balakrishnan, R ;
Cherry, JM ;
Christie, KR ;
Costanzo, MC ;
Dwight, SS ;
Engel, S ;
Fisk, DG ;
Hirschman, JE ;
Hong, EL ;
Nash, RS ;
Sethuraman, A ;
Theesfeld, CL ;
Botstein, D ;
Dolinski, K ;
Feierbach, B ;
Berardini, T ;
Mundodi, S ;
Rhee, SY ;
Apweiler, R ;
Barrell, D ;
Camon, E ;
Dimmer, E ;
Lee, V ;
Chisholm, R ;
Gaudet, P ;
Kibbe, W ;
Kishore, R ;
Schwarz, EM ;
Sternberg, P ;
Gwinn, M .
NUCLEIC ACIDS RESEARCH, 2004, 32 :D258-D261
[14]   The Digital Twin Throughout the SE Lifecycle [J].
Hause, Matthew .
INCOSE International Symposium, 2019, 29 (01) :203-217
[15]  
Kelemen ZD., 2013, TR201304
[16]   Modeling Inference Enterprises Using Multiple Interoperating Models [J].
Laskey, Kathryn Blackmond ;
Zaidi, Abbas ;
Buede, Dennis ;
Imran, Muhammad ;
Huang, Edward ;
Brown, David ;
Yousefi, Bahram ;
Matsumoto, Shou .
INCOSE International Symposium, 2018, 28 (01) :1764-1777
[17]  
Lee J.D., 2019, Systems Engineering in Context, P643, DOI [DOI 10.1007/978-3-030-00114-851, 10.1007/978-3-030-00114-851]
[18]   Towards Automating Design and Development of Inference Enterprise Models [J].
Lee, James D. ;
Matsumoto, Shou ;
Zaidi, Abbas K. ;
Laskey, Kathryn B. .
2019 13TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON), 2019,
[19]   Leveraging Digital Twin Technology in Model-Based Systems Engineering [J].
Madni, Azad M. ;
Madni, Carla C. ;
Lucero, Scott D. .
SYSTEMS, 2019, 7 (01)
[20]  
Morkevicius A., 2011, Making the most of an enterprise architecture modeling tool