This article presents a comprehensive systems-based approach to modelling, analysing, and evaluating the dynamics of cyberattacks, integrating event-driven simulation, graph-based representations of network infrastructures, a multilayer risk assessment model, the MITRE ATT&CK methodology, and time-based incident response performance indicators. The proposed model enables the formalization of adversarial behaviour, reconstruction of key stages of attack scenarios, and assessment of the impact of each attacker action on the overall security posture of an information system. The use of graph structures facilitates the identification of critical nodes, analysis of lateral movement, and estimation of the potential blast radius in the event of a successful intrusion. The multilayer risk model consolidates local events, node-level states, and global resilience indicators within a unified analytical framework. Particular attention is given to penetration testing as a core instrument of proactive cybersecurity. The findings demonstrate that integrating pentesting results into dynamic risk assessment models significantly enhances the accuracy and informational value of security evaluatio
📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً