Military-Based Cyber Risk Assessment Framework for Supporting Cyber Warfare in Thailand

Authors

  • Aniwat Hemanidhi Faculty of Information Technology Rangsit University, Thailand
  • Sanon Chimmanee Faculty of Information Technology Rangsit University, Thailand

DOI:

https://doi.org/10.32890/jict2017.16.2.1

Keywords:

Cyber risk assessment, risk management, cyber security, cyber warfare, Network Centric Warfare

Abstract

Information Technology (IT) Risk Management is designed to confirm the sufficiency of information security. There are many risk management/assessment standards, e.g. IS0 27005:2011 and NIST SP 800-30rev1, which are mainly designed for general organizations such as governments or businesses. Cyber risk assessment focused on military strategy has been rarely studied. Hence, this paper presents an innovative cyber risk assessment conceptual framework named “Cyber Risk Assessment (CRA)†which is extended from previous work with Military Risk Evaluation (MRE). This proposed CRA is the collection and integration of both quantitative and qualitative data. The Vulnerability Detection (VD) tools in Network Risk Evaluation (the previous studies) were used for the quantitative data collection and the focus group in the MRE (the proposed method) was used to collect qualitative data, which enhance the general risk assessment standard to achieve the objective of the research. The complexity of cyberspace domains with a military perspective is thoughtfully contemplated into the cyber risk assessment for national cyber security. Results of the proposed framework enable the possibility of cyber risk evaluation into score for national cyber security planning.

 

References

Andress, J., & Winterfeld, S. (2011). Cyber warfare: Techniques, tactics and tools for security practitioners. USA: Syngress. Cherdantseva, Y., Burnap, P., Blyth, A., Eden, P., Jones, K., Soulsby, H., &

Stoddart, K. (2016). A review of cyber security risk assessment methods for SCADA systems. Computers & Security on ScienceDirect, 1-27.

Chimmanee, S., Veeraprasit, T., Sriphrew, K., & Hemanidhi, A. (2012). A performance comparison of vulnerability detection between NetClarity Auditor and Open Source Nessus. Proceeding of the 3rd European Conference of Communications (ECCOM ’12), (pp. 280-285). Paris, France.

Cho, Y., Won, Y., & Cho, B. (2005). ITU-T X.805 based vulnerability analysis method for security framework of end-to-end network services. Proceedings of the 4th WSEAS Int. Conf. on Information Security, Communications and Computers, (pp. 228-292). Tenerife, Spain.

Creswell, J. W. (2014). Research design: Qualitative, quantitative, and mixed methods approaches (4th ed.). Thousand Oaks, CA: SAGE Publications, Inc.

Department of the Army (DOA). (2013). FM 3-13. Inform and influence activities. Washington DC, USA.

Department of the Army (DOA). (2012). ADRP 3-0. Unified land operations. Washington DC, USA. Journal of ICT, 16, No. 2 (Dec) 2017, pp: 192–

Department of the Army (DOA). (1994). FM 34-130. Intelligence preparation of the battlefield. Washington DC, USA.

Department of Defense (DOD). (2003). Network-centric warfare. Washington DC, USA.: Office of the Secretary of Defense.

Department of Defense (DOD). (2006). Joint publication 3-13. Information operations. USA: DOD Publications.

Department of Defense (DOD). (2011). Joint publication 3-0. Joint operations. USA: DOD Publications. Department of Defense (DOD) (2014). Joint publication 3-13. Information operations. (27 November 2012 Incorporating Change 1). USA: DOD Publications. Electronic Transactions Development Agency (ETDA) (2015). Thailand Internet user profile 2015. Bangkok, Thailand: Ministry of Information and Communication Technology.

Hemanidhi, A., Chimmanee, S., & Kimpan, C. (2015). Cyber risk evaluation framework based on risk environment of military operation. Asian Conference on Defence Technology (ACDT 2015) 2015. (pp. 42-47). Hua Hin: doi: 10.1109/ACDT.2015.7111581

Hemanidhi, A., Chimmanee, S., & Sanguansat, P. (2012). Risk evaluation by vulnerability detection tools for IT department of the Royal Thai Army. Proceeding of the 3rd European Conference of Communications (ECCOM ’12) (pp. 286-292). Paris, France: WSEAS Press.

Hemanidhi, A., Chimmanee, S., & Sanguansat, P. (2014). Network risk evaluation from security metric of vulnerability detection tools.

TENCON 2014-2014 IEEE Region 10 Conference (pp. 1-6). Bangkok: doi:10.1109/TENCON.2014.7022358

Hemanidhi, A., Chimmanee, S., Sanguansat, P., & Nuchampun, W. (2015, November). Cyber risk evaluation framework for network centric warfare. Journal of Converfence Information Technology (JCIT), 1-13.

Herzog, S. (2011). Revisiting the Estonian cyber attacks: Digital threats and multinational. Journal of Strategic Security, 49-60. Journal of ICT, 16, No. 2 (Dec) 2017, pp: 192– Information Organization for Standardization and the International Electrotechnical Commission (ISO/IEC) (2014, January 1). ISO/IEC 27000 (Information technology - Security techniques - Information security management systems - Overview and vocabulary) (3rd ed.). Geneva: ISO/IEC.

Information Systems Audit and Control Association. (ISACA). (2012). COBIT 5 (A business framework for the governance and management of enterprise IT). Rolling Meadows, IL: ISACA. International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC). (2013). ISO/IEC 27001:2013 Information security standard. Information security management system (ISMS). UK: British Standard (BSi). International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC). (2011). ISO/IEC 27005:2011 Information technology – Security techniques – Information security risk management (2nd ed.). Geneva: ISO/IEC

International Organization for Standardization (ISO). (2016, Jul 1). ISO 27799:2016 Health informatics - Information security management in health using ISO/IEC 27002 (2nd ed.). Geneva: ISO

International Organization for Standardization (ISO). (2009). ISO 31000:2009 Risk management – Principles and guidelines. Geneva: ISO.

Karnouskos, S. (2011). Stuxnet worm impact on industrial cyber-physical system security. IEEE Proceeding of the 37th Annual Conference on IEEE Industrial Electronics Society (IECON 2011), (pp. 280-285). Melbourne, Australia.

Kushner, D. (2013). IEEE SPECTRUM. The Real Story of Stuxnet [Online]. Retrieved from http://spectrum.ieee.org/telecom/security/the-realstory-of-stuxnet

Kwaak, J. S. (2014). The Wall Street Journal. South Korea nuclear plant operator hacked [Online]. Retrieved from http://www.wsj.com/articles/ south-korea-nuclear-plant-operator-hacked-1419237333 Journal of ICT, 16, No. 2 (Dec) 2017, pp: 192–

Loh, P. K. K., & Subramanian, D. (2010). Fuzzy classification metrics for scanner assessment and vulnerability reporting. IEEE Transaction on Information Forensics and Security, 5(4).

Mell, P., Scarfone, K., & Romanosky, S. (2007, June). CVSS: A Complete Guide to the Common Vulnerability Scoring System Version 2.0. Retrieved from The Forum of Incident Response and Security Teams (FIRST): https://www.first.org/cvss/v2/guide National Institute of Standards and Technology (NIST) (2008). NIST SPECIAL PUBLICATION 800-115 (Technical guide to information security testing and assessment). Geithersburg, MD: Computer Security Division, Information Technology Laboratory. National Institute of Standard and Technology (NIST) (2012). NIST SPECIAL PUBLICATION 800-30rev1 (Information security guide for conducting risk assessments). Gaithersburg, MD, US: Computer Security Division, Information Technology Laboratory. National Institute of Standards and Technology (NIST) (2015). NIST SPECIAL PUBLICATION 800-82r2 (Guide to industrial control systems (ICS) Security). Gaithersburg, MD: Stouffer, K., Pillitteri, V., Lightman, S., Abrams, M., & Hahn, A.

NetClarity, Inc. (2011). NACwall appliances user guide. Bedford, MA, USA.

Ophardt, J. A. (2010). Cyber warfare and the crime of aggression: The need for individual accountability on tomorrow’s battlefield. Duck Law & Technology Review, 1-28.

Singer, P., & Brooking, E. (2015, December 15). Terror on twitter : How ISIS is taking war to social media—and social media is fighting back. Retrieved from popular Science: http://www.popsci.com/terror-ontwitter-how-isis-is-taking-war-to-social-media

Steinberg, R.M., Everson, M. E. A., Martens, F. J., & Nottingham, L. E. (2004). Enterprise risk management integrated framework. USA: Committee of Sponsoring Organizations of the Treadway Commission (COSO).

Subramanian, D., Le, H. T., & Loh, P. K. K. (2009, May 24-28). Fuzzy heuristic design for diagnosis of web-based vulnerabilities. Fourth International Conference on internet monitoring and protection (ICIMP ‘09) (pp. 103-108). Venice/Mestre: doi: 10.1109/ICIMP.2009.25. Journal of ICT, 16, No. 2 (Dec) 2017, pp: 192–

Sun, K., Jajodia, S., Li, J., Cheng, W., Tang, W., & Singhal, A. (2010). Automatic security analysis using security metrics. The 2011 Military Communications Conference – Track 3 – Cyber Security and Network Operations, IEEE.

The MITRE Corporation. (1997-2017). Common vulnerabilities and exposures. Retrieved from Common Vulnerabilities and Exposures: https://cve.mitre.org/

Vitel, P. (2014, November 23). Cyber space and Euro-Atlantic security. France: Science and Technology Committee, NATO Parliamentary Assembly.

Downloads

Published

06-11-2017

How to Cite

Hemanidhi, A., & Chimmanee, S. (2017). Military-Based Cyber Risk Assessment Framework for Supporting Cyber Warfare in Thailand. Journal of Information and Communication Technology, 16(2), 192-222. https://doi.org/10.32890/jict2017.16.2.1

Research impact

Harvested 2026-09-06
10 citations, from OpenAlex — the highest of the sources checked

Counts differ between services because each indexes a different body of literature. None of them is the whole picture.

Identifiers DOI 10.32890/jict2017.16.2.1 OpenAlex W4245954199

Most read articles by the same author(s)