Search
Program Calendar
Browse By Day
Browse By Person
Browse By Room
Browse By Category
Browse By Session Type
Browse By Research Area
Search Tips
ASC Home
Personal Schedule
Sign In
X (Twitter)
This paper uses a Criminological framework and empirical evidence of observations and interviews done at two real-time cybersecurity events: (i) a force on force ("paintball") exercise held at the North American International Cyber Summit (NAICS), (ii) the US Industrial Control Systems Computer Emergency Response Team’s (ICS‐CERT) Red Team‐Blue Team cybersecurity training exercise held at Idaho National Laboratory (INL). This paper argues that understanding how adversaries adapt at various points in the attack path or intrusion chain is crucial in profiling adversaries and developing anticipatory cybersecurity measures. Specifically, the talk uses this empirical qualitative data to evaluate different intrusion chain models. It offers temporal metric analysis based on actual human behavior from the two real-time cybersecurity exercises. Finally, the paper discusses various modes of adaptation and group dynamics exhibited by red team members.