Using DESM to demonstrate how behavior can impact an enterprise's physical attack surface structure
Abstract
This paper addresses behaviors affecting the attack surface structure of a simulated enterprise model. The work conducted identifies human factors that contribute to the enterprise’s physical attack surface. Such factors can be social engineering, phishing, insider threats, inadequate employee awareness and training (AET), etc. By leveraging a Descriptive Enterprise System Model (DESM), we demonstrate how behavior impacts the enterprise's physical attack surface structure. The focus in this phase of the research is associating human factors that contribute to this condition. The model is leveraged to make two observations: (1) isolate behavior functionally as a factor impacting the enterprise’s physical attack surface and (2) isolate human factors as an indicator of an enterprise’s behavior.
Keywords: Next-Generation Cybersecurity, Enterprise Computing, Behavior-Based Cybersecurity, Physical Attack Surface, Human Factors In Information Management
DOI: 10.54941/ahfe1004760
Cite this paper
More from this volume
- Proposing a DESM-based analytical framework for the enterprise cyber defender
- Interactive virtual learning environment to develop next-generation cybersecurity practitioner competency
- Biometric Authentication for the Mitigation of Human Risk on a Social Network
- Measuring How Appropriate Individuals Are for Specific Jobs in a Network of Collaborators
- A Notion of Trustworthiness Based on Centrality in a Social Network
- Towards a Human-Centric AI Trustworthiness Risk Management Framework
- Does penalty help people learn to detect phishing emails?
- A survey of agent-based modeling for cybersecurity
- Mental Firewall Breached: Leveraging Cognitive Biases for Enhanced Cybersecurity
- Analyzing important factors in cybersecurity incidents using table-top exercise
- Discovering Cognitive Biases in Cyber Attackers’ Network Exploitation Activities: A Case Study
- Exploring User Perspectives on Prioritizing Security through Software Updates


AHFE Open Access