Skip to main content

Posts

Showing posts with the label argument-driven inquiry

A Standardized Vocabulary for Evaluating the Impact of Cyber Defense Decisions on Adversary Behavior

I. Introduction A. Background on cyber mission assurance decisions and their impact on cyber adversary behavior Cybersecurity is a critical component of modern society as almost every facet of our daily lives relies on computer systems and the internet. However, with the increasing dependence on these systems, cyber adversaries have become more sophisticated in their tactics, techniques, and procedures (TTPs) for exploiting vulnerabilities and causing harm. Cyber mission assurance decisions refer to the choices made by defenders in mitigating and managing the risk of cyber attacks against their systems, networks, and data. The impact of cyber mission assurance decisions on cyber adversary behavior is significant, as these decisions can affect the adversary's ability to launch successful attacks, the effectiveness of their TTPs, and the overall threat landscape. Thus, it is essential to have a standardized vocabulary for evaluating the impact of these decisions on adversary behavior...

Advancing Cyber Risk Assessment with Explainable AI and Scientific Methodology

I. Introduction Over the last decade, the cybersecurity industry has predominantly relied on quantitative analysis of historical data to measure and manage cyber risk. While this approach is useful in understanding past trends and patterns in cyber attacks, it may not provide an accurate reflection of the current threat landscape. The Digital Cyber Twin (DCT) approach offers a unique and innovative solution to support ongoing cyber risk assessment and decision-making by focusing on the present state rather than historical data. Through the use of automation, machine reasoning, and the scientific method, the DCT approach provides a more accurate and up-to-date view of an organization's security posture. By continuously collecting and analyzing various types of data, the DCT approach allows for the identification of emerging threats and the implementation of mitigation strategies. This approach is different from traditional quantitative analysis that focuses on historical data and ma...

Argument-Driven Inquiry (ADI) in STEM Education and Real-World Applications: Enhancing Scientific Reasoning and Problem-Solving Skills in Science, Math, and Engineering

Introduction: In today's world, the demand for STEM skills is growing rapidly, making it essential to provide a STEM education that focuses on building scientific reasoning and argumentation skills. One promising approach to STEM education is Argument-Driven Inquiry (ADI), which emphasizes the construction and defense of scientific claims based on scientific reasoning and data analysis. ADI has been used in various STEM courses from grade school to university levels to promote deeper understanding of scientific concepts and practices. Additionally, ADI can be applied in real-world contexts by STEM professionals to investigate complex phenomena, from subatomic particles to financial markets, and develop evidence-based solutions. In this paper, we will explore the use of ADI in STEM education and its real-world applications. We will also discuss how ADI can benefit employees by improving their problem-solving, decision-making, innovation, collaboration, and adaptability skills. ADI i...

Argument-Driven Inquiry for Selecting New Cybersecurity Technologies

As the threat landscape of cybersecurity continues to evolve, organizations must keep pace with the latest technologies and solutions to protect themselves against attacks. However, with so many options available, selecting the right cybersecurity technology can be a challenging task. That's where the framework of argument-driven inquiry (ADI) can be helpful. ADI is a problem-solving framework used in science education to help students develop critical thinking skills. It can also be applied to cybersecurity to help organizations select new technologies. The seven steps of ADI can guide organizations through the process of selecting the right cybersecurity technology: Identify a problem: The first step is to identify the problem that the organization is trying to solve. For example, the problem could be that the current security solution is not providing adequate protection against the latest threats. Develop a question: Once the problem has been identified, the next step is to dev...