<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2019.103006</article-id><article-id pub-id-type="publisher-id">JIS-93026</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Quantitative Evaluation of Cyber-Attacks on a Hypothetical School Computer Network
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Akinjide</surname><given-names>A. Akinola</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Adeyemi</surname><given-names>A. Adekoya</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Ayoade</surname><given-names>O. Kuye</given-names></name><xref ref-type="aff" rid="aff3"><sup>3</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Abiodun</surname><given-names>Ayodeji</given-names></name><xref ref-type="aff" rid="aff4"><sup>4</sup></xref></contrib></contrib-group><aff id="aff2"><addr-line>Virginia State University, Petersburg, VA, USA</addr-line></aff><aff id="aff4"><addr-line>Nuclear Power Plant Development Directorate, Nigeria Atomic Energy Commission, Abuja, Nigeria</addr-line></aff><aff id="aff1"><addr-line>University of Lagos, Lagos, Nigeria</addr-line></aff><aff id="aff3"><addr-line>University of Port Harcourt, Port Harcourt, Nigeria</addr-line></aff><pub-date pub-type="epub"><day>14</day><month>06</month><year>2019</year></pub-date><volume>10</volume><issue>03</issue><fpage>103</fpage><lpage>116</lpage><history><date date-type="received"><day>23,</day>	<month>January</month>	<year>2019</year></date><date date-type="rev-recd"><day>14,</day>	<month>June</month>	<year>2019</year>	</date><date date-type="accepted"><day>17,</day>	<month>June</month>	<year>2019</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  This paper presents the attack tree modeling technique of quantifying cyber-attacks on a hypothetical school network system. Attack trees are constructed by decomposing the path in the network system where attacks are plausible. Considered for the network system are two possible network attack paths. One network path represents an attack through the Internet, and the other represents an attack through the Wireless Access Points (WAPs) in the school network. The probabilities of success of the events, that is, 1) the attack payoff, and 2) the commitment of the attacker to infiltrate the network are estimated for the leaf nodes. These are used to calculate the Returns on Attacks (ROAs) at the Root Nodes. For Phase I, the “As Is” network, the ROA values for both attack paths, are higher than 7 (8.00 and 9.35 respectively), which are high values and unacceptable operationally. In Phase II, countermeasures are implemented, and the two attack trees reevaluated. The probabilities of success of the events, the attack payoff and the commitment of the attacker are then re-estimated. Also, the Returns on Attacks (ROAs) for the Root Nodes are re-assessed after executing the countermeasures. For one attack tree, the ROA value of the Root Node was reduced to 4.83 from 8.0, while, for the other attack tree, the ROA value of the Root Node changed to 3.30 from 9.35. ROA values of 4.83 and 3.30 are acceptable as they fall within the medium value range. The efficacy of this method whereby, attack trees are deployed to mitigate computer network risks, as well as using it to assess the vulnerability of computer networks is quantitatively substantiated.
 
</p></abstract><kwd-group><kwd>Cyber-Attack</kwd><kwd> Quantitative Vulnerability Assessment</kwd><kwd> Attack Trees</kwd><kwd> Return on Attack</kwd><kwd> Countermeasures</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>One of the most critical concerns of computer and IT professionals today is information security or the lack of it. There is a plethora of evidence to support such a claim. In this day and age, a computer cluster for cracking passwords can generate 350 billion password guesses per second and could break any eight-character password in a maximum of 5.5 hours. Internet web servers must resist thousands of attacks every day, and an unprotected computer connected to the Internet can be infected in fewer than 60 seconds. As it is with different industries and organizations, institutions of higher learning are not immune to this scourge. Moreover, the historic openness of higher education institutions to the public has made their computer networks even more vulnerable to cyber-attacks. Such vulnerabilities are discussed widely in extant literature. Assessment of the adverse impacts of information security vulnerabilities and threats in schools and academic environments has also been presented in contemporary literature. However, much of the reported work has been qualitative. While qualitative research can be useful, their conclusions are often subjective and lack details that provide the necessary impetus for clear and definitive actions, as the research outcomes do not readily lend themselves to risk controls and implementation. Clearly, there is a need to quantify the impacts of cyber-attacks on modern-day establishments, since the rate of cyber-attacks continues to escalate at an alarming rate. Quantitative methods of modeling and analyzing cyber threats have been of great interest to a group of researchers such as Greitzer et al. [<xref ref-type="bibr" rid="scirp.93026-ref1">1</xref>] , Xynos et al. [<xref ref-type="bibr" rid="scirp.93026-ref2">2</xref>] , WINS [<xref ref-type="bibr" rid="scirp.93026-ref3">3</xref>] [<xref ref-type="bibr" rid="scirp.93026-ref4">4</xref>] and Roger [<xref ref-type="bibr" rid="scirp.93026-ref5">5</xref>] [<xref ref-type="bibr" rid="scirp.93026-ref6">6</xref>] , who have all presented innovative approaches for analyzing cyber threats. Al-Mohannadi et al. [<xref ref-type="bibr" rid="scirp.93026-ref7">7</xref>] provided an insight into Cyber-attack modeling techniques. This review advances a significant array of and sheds further light on cyber-attack modeling. Further work by the same author, Al-Mohannadi, et al. [<xref ref-type="bibr" rid="scirp.93026-ref8">8</xref>] in particular, enunciated how Cyber Threat Intelligence could be gathered from Honeypot Data.</p><p>Furthermore, some quantitative studies carried out by Akinola et al., Baker, Balzarotti et al, Dacier et al., Edge et al., LeMay et al., and Mell et al. [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] - [<xref ref-type="bibr" rid="scirp.93026-ref15">15</xref>] used attack trees and their variants to examine and extend knowledge on the attributes of cyber-attack prone networks. Attack trees are illustrations of network systems whereby, an asset, or target, may be compromised. Attack trees present interdependencies between attack paths by breaking down the complexity of the network system and decomposing high-level parent goals into the smaller subtasks. Amenaza [<xref ref-type="bibr" rid="scirp.93026-ref16">16</xref>] indicates that the basic premise of an attack tree model is the elucidation of the vulnerability of the system, and ultimately, to isolate and report what is needed to achieve desired remedial outcome and success. A set of tools was developed by Dacierel et al. [<xref ref-type="bibr" rid="scirp.93026-ref12">12</xref>] which provides automatic security evaluations of UNIX-based systems. The tools are based on modeling a network system, which transforms the privilege graphs into a Markov chain with all the corresponding possible successful attack scenarios.</p><p>Balzarotti et al. [<xref ref-type="bibr" rid="scirp.93026-ref11">11</xref>] discusses how relevant information on the attributes of the architecture, and the vulnerabilities inherent in a distributed system can be applied quantitatively, to assess the risk to which the network systems are exposed. The advantage of this approach to risk evaluation is its capability to evaluate the extent to which one should believe in system integrity and trustworthiness, and facilitates a comparative analysis of different evaluative outcomes.</p><p>Another line of research is studying security measures for mobile ad-hoc networks, using attack and protection trees. The work of Edge et al. [<xref ref-type="bibr" rid="scirp.93026-ref13">13</xref>] indicated that Defense-trees could be used to mitigate or even eliminate vulnerabilities. There are a few limiting factors here, to the extent that some of the defense trees have overpopulated and thereby become redundant. Also, some factors such as the commitment of the attacker, that is, the willpower that the threat agent exhibits, and the time committed to the pursuit of the goal intended are neglected in these models.</p><p>Lemay et al. [<xref ref-type="bibr" rid="scirp.93026-ref14">14</xref>] calculated the State-based Security metrics of two variants of a Supervisory Control and Data Acquisition (SCADA) system architecture using the AD Versary VIew Security Evaluation (ADVISE) technique. The study demonstrates how the quantitative metrics produced by ADVISE can aid system design and provide much insight on system security. Akinola et al. [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] quantitatively evaluated the effect of cyber-attacks on a school network system. Their work involved evaluating information security as proposed by Cremonini and Martini [<xref ref-type="bibr" rid="scirp.93026-ref17">17</xref>] , who used the Return-on-Attack (ROA) and the Return-On-Investment (ROI) methodologies and metrics, to assess and measure how an attacker’s preference changes with the selected security measure. Furthermore, Akinola et al. [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] established that by executing specific countermeasures, the risk of cyber-attacks on a school network attack surface could be greatly reduced. The current work builds on previously established foundations; it applies a similar method to a different environment that is, a dissimilar school network system. It is relevant to point out that, while Akinola et al. [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] previous work used single values for the leaf nodes; this study extends the former by using randomly generated values to denote the leaf nodes.</p></sec><sec id="s2"><title>2. Methodology</title><sec id="s2_1"><title>2.1. Network Description</title><p>The network which is the test-bed for the study is a school computer network, consisting of the following elements—an Internet router (Cisco 890), a Fast Ethernet switch 1 (core switch, Cisco SFS3500) and an Ethernet switch 2 (Cisco SFE2000). Included in the network are Wireless Access Points (Linksys WAP300N), a Web server, a database server, and a Mikrotik firewall. The Internet router connects to the web server (Apache HTTP) in the computer laboratory on the school premises. The workstations (running on Windows 2007), are of the ring-based topology. A database server (MYSQL) houses the records of graduates and matriculated students of the school at that time. The attacker profiled for this network is a disgruntled ex-student, whose motivation, is the will to compromise the database server that hosts the students’ valuable records, with the aim of modifying some of the data items including his.</p></sec><sec id="s2_2"><title>2.2. The Attack Tree Model</title><p>For the attacker to commit his infamous act, and to compromise the database remotely, the attacker uses one of the wireless access points in the school vicinity. <xref ref-type="fig" rid="fig2">Figure 2</xref> and <xref ref-type="fig" rid="fig3">Figure 3</xref> depict the architecture of the school’s network as well as the attack trees. The Attack goal is to compromise the database server—the root node. The tasks needed to achieve success on the attack are spelt out in <xref ref-type="fig" rid="fig2">Figure 2</xref> and <xref ref-type="fig" rid="fig3">Figure 3</xref>. Each task is conceptually launched at a node in the attack tree. These are wireless access points 1 and 2 in <xref ref-type="fig" rid="fig1">Figure 1</xref>. <xref ref-type="fig" rid="fig2">Figure 2</xref> is a schematic diagram of the various tasks that are involved, and it represents an attack via wireless access points, while <xref ref-type="fig" rid="fig3">Figure 3</xref> depicts an attack through the Internet. In <xref ref-type="fig" rid="fig2">Figure 2</xref> and <xref ref-type="fig" rid="fig3">Figure 3</xref>, the nodes that are conjoined by an arc must be performed simultaneously for an attack to be successful, while those that are not, requires either of the nodes for success. Mathematically, this can be represented using the Boolean notations, i.e., “AND” or “OR” respectively. Akinola et al. [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] have represented the Return-on-Attack (ROA) formulation used in this work as follows:</p><p>R O A = P o C P s (1)</p><p>where:</p><p>P<sub>o</sub> = payoff; C = commitment; P<sub>s</sub> = probability of success.</p><p>The Commitment, C, is assumed to have a unit value because credible attackers have the capability and the intention to exploit a node contemporaneously. The ROA values range from 1 to 10 and are Low, Medium, High and Very High</p><p>[<xref ref-type="bibr" rid="scirp.93026-ref13">13</xref>] . Low ROA values range from 1 - 3. In such a scenario, the attack’s impact is minor, and it could easily be detected and repaired. Medium ROA values are between 4 and 6, the attack’s impact on the network is usually, “Moderate”; there is typically a reduced performance or interruptions in resource availability. Furthermore, in Attack trees with moderate ROA values, the integrity, confidentiality, and availability of the network require special effort to detect and repair. High ROA values are between 7 and 9. In this case, the attack’s impact on the network is “Severe”; leading to significant damage to the network system; there are essential informational access and disclosure to some system files. Considerable effort is required to detect and repair the damage on such networks. When the ROA value is 10, the network system is compromised completely, inoperable or destroyed. The attack vector can render the asset completely unavailable, in this case.</p><p>The probability of success is calculated using Equation (2) [<xref ref-type="bibr" rid="scirp.93026-ref9">9</xref>] :</p><p>P s = A c v ∗ C A ∗ A u (2)</p><p>where</p><p>A c v = Access Vector, C A = Access Complexity, and A u = Authentication.</p><p>The access vector ( A c v ) shows how vulnerabilities may be exploited. The access complexity ( C A ) metric describes how easy or difficult it is to exploit the exposed vulnerability. The number of times that an attacker can be authenticated to a target node for exploitation is indicated by the authentication ( A u ) metric. However, successful authentication is not taken into account. For locally exploitable vulnerabilities, this value should only be set to single or multiple values if further authentication is required after initial access. Numerical values for the Access Vector, Access Complexity, and Authentication are derived from a common vulnerability scoring system guide [<xref ref-type="bibr" rid="scirp.93026-ref17">17</xref>] . The probabilities for the intermediate and root nodes P<sub>o</sub> and P<sub>s</sub> are calculated using Equation (3), (4), (5) and (6) [<xref ref-type="bibr" rid="scirp.93026-ref13">13</xref>] :</p><p>For “AND” nodes:</p><p>P s = ∏ i = 1 k prob i (3)</p><p>P o = 10 k − ∏ i = 1 k ( 10 − payoff ) 10 k − 1 (4)</p><p>For “OR” nodes</p><p>P s = 1 − ∏ i = 1 k ( 1 − prob i ) (5)</p><p>P o = max i = 1 k payoff i (6)</p><p>where</p><p>Prob ∈ ( 0 , 1 ) ; Payoff ∈ [ 1 , 10 ] , k = number of leaf nodes.</p></sec></sec><sec id="s3"><title>3. Results and Discussion</title><p>Again, <xref ref-type="fig" rid="fig2">Figure 2</xref> and <xref ref-type="fig" rid="fig3">Figure 3</xref>, present the two Attack Trees A and B examined in this study. The Payoff, Access Vector, Access Complexity and Authentication values for the two Attack trees which tally with expert opinions, are presented in <xref ref-type="table" rid="table1">Table 1</xref> and <xref ref-type="table" rid="table2">Table 2</xref>. The Payoff, Access Vector, Access Complexity and Authentication values are used to calculate the ROA values for the leaf and intermediate nodes. These values are subsequently used to calculate the ROA values required to compromise the database for Attack Trees A and B (<xref ref-type="fig" rid="fig1">Figure 1</xref> and <xref ref-type="fig" rid="fig2">Figure 2</xref>). The ROA values obtained at the root nodes (RN) are 8.00 and 9.35 for Attack Trees A and B respectively. These ROA values fall in the High range, implying that both root nodes can be exploited easily.</p><p>With Attack Tree A (<xref ref-type="fig" rid="fig2">Figure 2</xref>), the attacker severely impacted the network system thereby, causing considerable informational disclosure and access to many system files, while with Attack Tree B (<xref ref-type="fig" rid="fig3">Figure 3</xref>), the attacker rendered the resource completely unavailable.</p><p>It must be pointed out that given that the reported values in <xref ref-type="table" rid="table1">Table 1</xref> and <xref ref-type="table" rid="table2">Table 2</xref>, may not reflect the actual real-life situations. Therefore, the access vectors, access complexities, and authentication values were varied randomly within a 5%, 10%, 20%, 30%, 40% and 50% range of the expert opinion values presented</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Parameters used in calculating ROA for Attack Tree A</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Node</th><th align="center" valign="middle" >Task name</th><th align="center" valign="middle" >Payoff</th><th align="center" valign="middle" >Access Vector (A<sub>V</sub>)</th><th align="center" valign="middle" >Access Complexity (C<sub>A</sub>)</th><th align="center" valign="middle" >Authentication (A<sub>U</sub>)</th></tr></thead><tr><td align="center" valign="middle" >LN1</td><td align="center" valign="middle" >Social Engineering on Work Station</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.40</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN2</td><td align="center" valign="middle" >Brute Force on Admin</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.60</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN3</td><td align="center" valign="middle" >Packet Sniffing</td><td align="center" valign="middle" >4</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.60</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN4</td><td align="center" valign="middle" >MAC Address Spoofing</td><td align="center" valign="middle" >5</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.90</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN5</td><td align="center" valign="middle" >Spoofing Username &amp; Password</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.60</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN6</td><td align="center" valign="middle" >Man-in-the-Middle Attack</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.36</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN7</td><td align="center" valign="middle" >Run Arbitrary Code on LAN</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.85</td><td align="center" valign="middle" >1</td></tr></tbody></table></table-wrap><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Parameters used in calculating ROA for Attack Tree B</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Node</th><th align="center" valign="middle" >Task name</th><th align="center" valign="middle" >Payoff</th><th align="center" valign="middle" >Access Vector (A<sub>V</sub>)</th><th align="center" valign="middle" >Access Complexity (C<sub>A</sub>)</th><th align="center" valign="middle" >Authentication (A<sub>U</sub>)</th></tr></thead><tr><td align="center" valign="middle" >LN1</td><td align="center" valign="middle" >Synful Knock</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.70</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN2</td><td align="center" valign="middle" >MAC Address Spoofing</td><td align="center" valign="middle" >5</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.90</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN3</td><td align="center" valign="middle" >Exploit Winbox Proxy</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.60</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN4</td><td align="center" valign="middle" >Bypass Ipsec via Tunnel Traffic</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.60</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN5</td><td align="center" valign="middle" >Install Rootkit</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.40</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN6</td><td align="center" valign="middle" >Man-in-the-Middle Attack</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.36</td><td align="center" valign="middle" >1</td></tr><tr><td align="center" valign="middle" >LN7</td><td align="center" valign="middle" >Run Arbitrary Code on LAN</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.80</td><td align="center" valign="middle" >1</td></tr></tbody></table></table-wrap><p>in <xref ref-type="table" rid="table2">Table 2</xref> and <xref ref-type="table" rid="table3">Table 3</xref>. The calculations for ROA were performed 10,000 times to simulate more probable situations. The results obtained are shown in <xref ref-type="fig" rid="fig4">Figure 4</xref> and <xref ref-type="fig" rid="fig5">Figure 5</xref> for Attack Trees A and B respectively.</p><p><xref ref-type="fig" rid="fig4">Figure 4</xref> shows that for Attack Tree A, the maximum and minimum ROA values are 7.98 and 8.00 when the access vectors, access complexities, and authentication values are varied randomly within +50% of expert opinion. The average ROA for the attack path is 7.99. The implication is that for these Attack trees, the ROA value is always high even when errors exist in estimating key parameters.</p><p>Also, the maximum and minimum ROA values vary from 9.40 to 5.86 for the Attack Tree B (<xref ref-type="fig" rid="fig5">Figure 5</xref>) when the Access Vectors, Access Complexities, and Authentication values are also varied randomly within &#177;50% of expert opinion values. The average ROA for the Attack path is 9.12, which means that for half of the time, the ROA value is greater than 9.00; a High ROA value which may be unacceptable. Clearly, the ROA values in both the Attack Trees A and B are high. The implication is that an upgrade of the two trees is needed to reduce their vulnerability. <xref ref-type="fig" rid="fig6">Figure 6</xref> and <xref ref-type="fig" rid="fig7">Figure 7</xref>, present the suggested upgrade Attack trees.</p><p>All things considered, the recommended security upgrades to be implemented on leaf nodes on the Attack Trees are:</p><p>1) Adding Intrusion Detection and Prevention Systems (IDPS) at ‘sensors’ on the network diagram.</p><p>2) Adding Remote Access Servers (RAS) before the business processing unit of the digital Network, as all inbound and outbound traffic is routed through this unit.</p><p>Again, new Access Vectors, Access Complexities, and Authentication values were obtained for the Attack Trees A and B, by expert judgment. These values are shown in <xref ref-type="table" rid="table3">Table 3</xref> and <xref ref-type="table" rid="table4">Table 4</xref> for the Attack Trees A and B respectively.</p><p>The ROA values for the nodes are re-calculated, and the results are presented in <xref ref-type="fig" rid="fig6">Figure 6</xref> and <xref ref-type="fig" rid="fig7">Figure 7</xref> for the upgraded Attack Trees A and B respectively. The ROA values at the root nodes are 4.32 and 3.30 for Attack Trees A and B respectively. These ROA values are lower than the values reported before the</p><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> Parameters used in calculating ROA for Attack Tree B after upgrade</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Node</th><th align="center" valign="middle" >Task name</th><th align="center" valign="middle" >Payoff</th><th align="center" valign="middle" >Access Vector (A<sub>V</sub>)</th><th align="center" valign="middle" >Access Complexity (C<sub>A</sub>)</th><th align="center" valign="middle" >Authentication (A<sub>U</sub>)</th></tr></thead><tr><td align="center" valign="middle" >LN1</td><td align="center" valign="middle" >Social Engineering</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN2</td><td align="center" valign="middle" >Brute Force</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.7</td></tr><tr><td align="center" valign="middle" >LN3</td><td align="center" valign="middle" >Packet Sniffing</td><td align="center" valign="middle" >4</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN4</td><td align="center" valign="middle" >MAC Address Spoofing</td><td align="center" valign="middle" >5</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN5</td><td align="center" valign="middle" >Spoof Username &amp; Password</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.7</td></tr><tr><td align="center" valign="middle" >LN6</td><td align="center" valign="middle" >Man-in-the-Middle Attack</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.3</td><td align="center" valign="middle" >0.53</td></tr><tr><td align="center" valign="middle" >LN7</td><td align="center" valign="middle" >Run Arbitrary Code on LAN</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >0.85</td><td align="center" valign="middle" >0.28</td><td align="center" valign="middle" >0.4</td></tr></tbody></table></table-wrap><p>upgrades, and the ROA values fell to the medium score range for ROA values. Thus, the suggested upgrades were effective. Hence, they did reduce the vulnerability to compromise the Database.</p><p>To further obtain better estimates of the ROA values at the Root nodes for each Attack Tree, repeated calculations were performed by randomly varying</p><p>Access Vector, Access Complexity, and Authentication values up to the +50% range. The calculations were performed 10,000 times with randomly generated values of Access Vectors, Access Complexities, and Authentication. A summary of the results is shown graphically in <xref ref-type="fig" rid="fig8">Figure 8</xref> and <xref ref-type="fig" rid="fig9">Figure 9</xref> for Attacks Trees A and B respectively. Again, the results indicate that the error in ROA value increases proportionally with estimated errors in Access Vector, Access Complexity, and Authentication values; however, the ROA values average out to the values obtained in <xref ref-type="fig" rid="fig6">Figure 6</xref> and <xref ref-type="fig" rid="fig7">Figure 7</xref> for the Attack Tree A and B respectively.</p></sec><sec id="s4"><title>4. Conclusion</title><p>Considered in this study, are two attack scenarios on compromising a database in a school network. The networks were analyzed quantitatively, using the attack tree method. The ROA for each attack scenario was determined, and in both cases, they turned out to be &gt;7.0; which meant they are in the high range band. The implication is that the database could be compromised easily. When suggested upgrades were implemented, the ROA values reduced to 4.32 and 3.30 for</p><table-wrap id="table4" ><label><xref ref-type="table" rid="table4">Table 4</xref></label><caption><title> Parameters used in calculating ROA for Attack Tree B after upgrade</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Node</th><th align="center" valign="middle" >Task name</th><th align="center" valign="middle" >Payoff</th><th align="center" valign="middle" >Access Vector (A<sub>V</sub>)</th><th align="center" valign="middle" >Access Complexity (C<sub>A</sub>)</th><th align="center" valign="middle" >Authentication (A<sub>U</sub>)</th></tr></thead><tr><td align="center" valign="middle" >LN1</td><td align="center" valign="middle" >Synful Knock</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN2</td><td align="center" valign="middle" >MAC Address Spoofing</td><td align="center" valign="middle" >5</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.7</td></tr><tr><td align="center" valign="middle" >LN3</td><td align="center" valign="middle" >Exploit Winbox Proxy</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN4</td><td align="center" valign="middle" >Bypass Ipsec via Tunnel Traffic</td><td align="center" valign="middle" >7</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN5</td><td align="center" valign="middle" >Install Rootkit</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.7</td></tr><tr><td align="center" valign="middle" >LN6</td><td align="center" valign="middle" >Man-in-the-middle Attack</td><td align="center" valign="middle" >6</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.4</td></tr><tr><td align="center" valign="middle" >LN7</td><td align="center" valign="middle" >Run Arbitrary Code on LAN</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >0.6</td><td align="center" valign="middle" >0.4</td><td align="center" valign="middle" >0.4</td></tr></tbody></table></table-wrap><p>Attack Tree A and Attack Tree B respectively. The ROA values are acceptable because they fall in the Medium range. Even when errors in the Access Vector, Access Complexity, and Authentication values were used to calculate the ROA values, the values fell within the 4 - 7 range, which is an acceptable bound. The</p><p>results of the study held steady. The method can, therefore, be used to mitigate, and by extension, to assess the vulnerability of computer networks quantitatively.</p></sec><sec id="s5"><title>Conflicts of Interest</title><p>The authors declare no conflicts of interest regarding the publication of this paper.</p></sec><sec id="s6"><title>Cite this paper</title><p>Akinola, A.A., Adekoya, A.A., Kuye, A.O. and Ayodeji, A. (2019) Quantitative Evaluation of Cyber-Attacks on a Hypothetical School Computer Network. Journal of Information Security, 10, 103-116. https://doi.org/10.4236/jis.2019.103006</p></sec><sec id="s7"><title>Nomenclature</title><p>A<sub>cv</sub></p><p>Access Vector</p><p>A<sub>u</sub></p><p>Authentication</p><p>C</p><p>Commitment</p><p>C<sub>A</sub></p><p>Access Complexity</p><p>IN</p><p>Intermediate Node</p><p>LN</p><p>Leaf Node</p><p>P<sub>o</sub></p><p>Payoff</p><p>P<sub>s</sub></p><p>Probability of Success</p><p>R</p><p>Returns on Attack</p><p>RN</p><p>Root Node</p><p>ROA</p><p>Returns on Attack</p><p>ROI</p><p>Return on Investment</p><p>WAP</p><p>Wireless Access Points</p></sec></body><back><ref-list><title>References</title><ref id="scirp.93026-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Greitzer, F.L., Paulson, P.R., Kangas, L.J., Franklin, L., Edgar, T.W. and Frincke, D.A. (2009) Assessment Challenges: Validating the Model. PNNL Technical Report, Richard.</mixed-citation></ref><ref id="scirp.93026-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Xynos, K., Sutherland, I., Read, H., Everitt, E. and Blyth, A.J.C. (2010) Penetration Testing and Vulnerability Assessments: A Professional Approach. International Cyber Resilience Conference, Perth, 23-14 August 2010, 126-132.</mixed-citation></ref><ref id="scirp.93026-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">World Institute for Nuclear Security (2012) Human Reliability as a Factor in Nuclear Security. Presented at the A WINS International Best Practice Guide for Your Organization. Vienna.</mixed-citation></ref><ref id="scirp.93026-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">World Institute for Nuclear Security (2015) Managing Internal Threat. A WINS International Best Practice Guide for Your Organization. Vienna.</mixed-citation></ref><ref id="scirp.93026-ref5"><label>5</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Roger</surname><given-names> G.J. </given-names></name>,<etal>et al</etal>. (<year>2010</year>)<article-title>Changing Security Paradigms</article-title><source> Journal of Physical Security</source><volume> 4</volume>,<fpage> 35</fpage>-<lpage>47</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.93026-ref6"><label>6</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Roger</surname><given-names> G.J. </given-names></name>,<etal>et al</etal>. (<year>2010</year>)<article-title>Being Vulnerable to the Threat of Confusing Threats with Vulnerabilities</article-title><source> Journal of Physical Security</source><volume> 4</volume>,<fpage> 30</fpage>-<lpage>34</lpage>.<pub-id pub-id-type="doi"></pub-id></mixed-citation></ref><ref id="scirp.93026-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Al-Mohannadi, H., Mirza, Q., Namanya, A., Awan, I., Cullen, A. and Disso, J. (2016) Cyber-Attack Modeling Analysis Techniques: An Overview. IEEE 4th International Conference on Future Internet of Things and Cloud Workshops, Vienna, 22-24 August 2016, 69-76. https://doi.org/10.1109/W-FiCloud.2016.29</mixed-citation></ref><ref id="scirp.93026-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Almohannadi, H., Awan, I., Al Hamar, J., Cullen, A., Disso, J.P. and Armitage, L. (2018) Cyber Threat Intelligence from Honeypot Data Using Elasticsearch. IEEE 32nd International Conference on Advanced Information Networking and Applications, Cracow, 16-18 May 2018, 900-906. https://doi.org/10.1109/AINA.2018.00132</mixed-citation></ref><ref id="scirp.93026-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">Akinola, A.A., Kuye, A.O. and Ayodeji, A. (2014) Cyber-Attacks Analysis of a School Network. 55th Annual Meeting of Institute of Nuclear Materials Management, Atlanta, 20-24 July 2014.</mixed-citation></ref><ref id="scirp.93026-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Baker, W. (2007) Necessary Measures: Metric-Driven Information Security Risk Peltier Assessment and Decision Making. Communications of the ACM, 50, 101-106.  
https://doi.org/10.1145/1290958.1290969</mixed-citation></ref><ref id="scirp.93026-ref11"><label>11</label><mixed-citation publication-type="book" xlink:type="simple">Balzarotti, D., Monga, M. and Sicari, S. (2006) Assessing the Risk of Using Vulnerable Components. In: Gollmann, D., Massacci, F. and Yautsiukhin, A., Eds., Quality of Protection, Advances in Information Security, Vol. 23, Springer US, Boston, 65-77.  
https://doi.org/10.1007/978-0-387-36584-8_6</mixed-citation></ref><ref id="scirp.93026-ref12"><label>12</label><mixed-citation publication-type="book" xlink:type="simple">Dacier, M., Deswarte, Y. and Kaaniche, M. (1996) Models and Tools for Quantitative Assessment of Operational Security. In: Katsikas, S.K. and Gritzalis, D., Eds., Information Systems Security, Springer US, Boston, 177-186.  
https://doi.org/10.1007/978-1-5041-2919-0_15</mixed-citation></ref><ref id="scirp.93026-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Edge, K.S., Raines, R.A., Baldwin, R.W., Grimaila, M.R., Bennington, R.W. and Reuter, C.E. (2007) Analyzing Security Measures for Mobile Ad Hoc Networks Using Attack and Protection Trees. Journal of Information Warfare, 6, 25-38.</mixed-citation></ref><ref id="scirp.93026-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">LeMay, E., Ford, M.D., Keefe, K., Sanders, W.H. and Muehrcke, C. (2011) Model-Based Security Metrics Using Adversary View Security Evaluation (ADVISE). Eighth International Conference on Quantitative Evaluation of Systems, Aachen, 5-8 September 2011, 191-200. https://doi.org/10.1109/QEST.2011.34</mixed-citation></ref><ref id="scirp.93026-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Mell, P., Scarfone, K. and Romanosky, S. (2006) Common Vulnerability Scoring System. IEEE Security &amp; Privacy, 4, 85-89. https://doi.org/10.1109/MSP.2006.145</mixed-citation></ref><ref id="scirp.93026-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Amenaza Technologies Limited (2005) Fundamentals of Capabilities-Based Attack Tree Analysis. Calgary, 25.</mixed-citation></ref><ref id="scirp.93026-ref17"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Cremonini, M. and Martini, P. (2005) Evaluating Information Security Investments from Attackers Perspective: The Return-on-Attack (ROA). 4th Workshop on the Economics on Information Security, Cambridge, 1-3 June 2005.</mixed-citation></ref></ref-list></back></article>