{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T13:45:03Z","timestamp":1777902303230,"version":"3.51.4"},"reference-count":39,"publisher":"SAGE Publications","issue":"9","license":[{"start":{"date-parts":[[2014,7,3]],"date-time":"2014-07-03T00:00:00Z","timestamp":1404345600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["SIMULATION"],"published-print":{"date-parts":[[2014,9]]},"abstract":"<jats:p>The aim of this work is to propose a framework for the distributed simulation of cyber attacks based on high-level architecture (HLA), which is a commonly used standard for distributed simulations. The proposed framework and the corresponding simulator, which is called the distributed cyber attack simulator (abbreviated by DCAS), help administrators to model and evaluate the security measures of the networks. At the core of the DCAS is a simulation engine based on Portico, which is an open source HLA run-time infrastructure. The DCAS works in two modes: interactive and automated. Three types of simulation components (which are called federates in HLA terminology) are considered in the framework: the (1) network federate, (2) attacker federate and (3) defender federate. The simulator provides features for graphical design of the network models, animated traffic simulation, data collection, statistical analysis and different consoles for attacking and defending elements (e.g., intrusion detection systems, intrusion prevention systems). To increase the fidelity of the simulation outputs, real-world payloads are used by the DCAS. All the exploits information and the parameters of various network elements are automatically extracted from the open source vulnerability database. Also, the Snort rule-set is used as the signature database of the defending elements. The architecture and algorithms of the DCAS and the corresponding underlying simulation engine plus the security evaluation results of two illustrative examples are presented in this paper.<\/jats:p>","DOI":"10.1177\/0037549714540221","type":"journal-article","created":{"date-parts":[[2014,7,3]],"date-time":"2014-07-03T23:38:51Z","timestamp":1404430731000},"page":"1071-1102","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":7,"title":["A distributed simulation framework for modeling cyber attacks and the evaluation of security measures"],"prefix":"10.1177","volume":"90","author":[{"given":"Mehrdad","family":"Ashtiani","sequence":"first","affiliation":[{"name":"Trustworthy Computing Laboratory, School of Computer Engineering, Iran University of Science and Technology, Tehran, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Abdollahi Azgomi","sequence":"additional","affiliation":[{"name":"Trustworthy Computing Laboratory, School of Computer Engineering, Iran University of Science and Technology, Tehran, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2014,7,3]]},"reference":[{"key":"bibr1-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2013.03.011"},{"key":"bibr2-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/NCA.2013.18"},{"key":"bibr3-0037549714540221","volume-title":"proceedings of the first secure control systems workshop","author":"Chabukswar R"},{"key":"bibr4-0037549714540221","doi-asserted-by":"publisher","DOI":"10.5772\/46961"},{"key":"bibr5-0037549714540221","first-page":"705","volume-title":"proceedings of the 14th workshop on standards for the interoperability of defence simulations","author":"Calvin JO"},{"key":"bibr6-0037549714540221","first-page":"265","volume-title":"proceedings of the 18th European simulation multiconference. Networked simulations and simulation networks","author":"Troitzsch KG"},{"key":"bibr7-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1145\/1456645.1456649"},{"key":"bibr8-0037549714540221","doi-asserted-by":"publisher","DOI":"10.2200\/S00046ED1V01Y200609CNT001"},{"key":"bibr9-0037549714540221","first-page":"1907","volume-title":"proceedings of the 2010 IEEE conference on education engineering (EDUCON)","author":"Pastor V"},{"key":"bibr10-0037549714540221","first-page":"421","volume-title":"proceedings of the international conference on computational intelligence and security (CIS\u201908)","author":"Xin-lei L"},{"key":"bibr11-0037549714540221","first-page":"6","volume-title":"proceedings of the 2nd international conference on simulation tools and techniques","author":"Channakeshava K"},{"key":"bibr12-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/TSMCC.2010.2048428"},{"key":"bibr13-0037549714540221","first-page":"1180","volume-title":"proceedings of the 39th conference on winter simulation: 40 years! The best is yet to come","author":"Kuhl ME"},{"key":"bibr14-0037549714540221","volume-title":"Development of a cyber attack simulator for network modeling and cyber security analysis","author":"Costantini KC","year":"2007"},{"key":"bibr15-0037549714540221","first-page":"3","volume-title":"proceedings of the security education and critical infrastructures","author":"Vigna G"},{"key":"bibr16-0037549714540221","first-page":"63","volume-title":"proceedings of the international society of optics and photonics (AeroSense\u201903)","author":"Brown B"},{"key":"bibr17-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/ICCMS.2009.52"},{"key":"bibr18-0037549714540221","first-page":"4","volume-title":"proceedings of the 2nd international conference on simulation tools and techniques","author":"Futoransky A"},{"key":"bibr19-0037549714540221","first-page":"119","volume-title":"proceedings of the workshop on principles of advanced and distributed simulation (PADS 2005)","author":"Liljenstam M"},{"key":"bibr20-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1177\/0037549708088956"},{"key":"bibr21-0037549714540221","first-page":"35","volume-title":"proceedings of the 1st international conference on simulation tools and techniques for communications, networks and systems and workshops","author":"Leszczyna R"},{"key":"bibr22-0037549714540221","first-page":"487","volume-title":"proceedings of the systems modeling and simulation: theory and applications","author":"Yun JB"},{"key":"bibr23-0037549714540221","first-page":"37","volume-title":"proceedings of the 2009 workshop on new security paradigms","author":"Verendel V"},{"key":"bibr24-0037549714540221","volume-title":"The fundamentals of network security","author":"Canavan JE","year":"2001"},{"key":"bibr25-0037549714540221","volume-title":"Computer Security Handbook","author":"Bosworth S","year":"2002"},{"key":"bibr26-0037549714540221","volume-title":"Counter hack reloaded: a step-by-step guide to computer attacks and effective defenses","author":"Skoudis E","year":"2005"},{"key":"bibr27-0037549714540221","volume-title":"Microsoft encyclopedia of security","author":"Tulloch M","year":"2003"},{"key":"bibr28-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1177\/0037549704047602"},{"key":"bibr29-0037549714540221","first-page":"053","volume":"9","author":"Wang HB","year":"2005","journal-title":"Computer Simulation"},{"key":"bibr30-0037549714540221","volume-title":"proceedings of the 48th international astronautical congress","author":"Jense G"},{"key":"bibr31-0037549714540221","first-page":"116","volume-title":"proceedings of the 11th IEEE\/ACM international symposium on modeling, analysis and simulation of computer telecommunications systems (MASCOTS 2003)","author":"Fujimoto RM"},{"key":"bibr32-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1145\/361026.361034"},{"key":"bibr33-0037549714540221","volume-title":"Modeling of internet traffic: internet access influence, user interference, and tcp behavior","author":"Vicari N","year":"2003"},{"key":"bibr34-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/4236.968834"},{"key":"bibr35-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/90.392383"},{"key":"bibr36-0037549714540221","first-page":"267","volume-title":"proceedings of the 10th ACM SIGCOMM conference on internet measurement","author":"Benson T"},{"key":"bibr37-0037549714540221","doi-asserted-by":"publisher","DOI":"10.1109\/4234.831037"},{"key":"bibr38-0037549714540221","first-page":"247","volume-title":"proceedings of the managing cyber threats","author":"Jajodia S"},{"key":"bibr39-0037549714540221","volume-title":"Metasploit toolkit for penetration testing, exploit development, and vulnerability research","author":"Maynor D","year":"2011"}],"container-title":["SIMULATION"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549714540221","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.1177\/0037549714540221","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.1177\/0037549714540221","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T11:25:35Z","timestamp":1777634735000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.1177\/0037549714540221"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014,7,3]]},"references-count":39,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2014,9]]}},"alternative-id":["10.1177\/0037549714540221"],"URL":"https:\/\/doi.org\/10.1177\/0037549714540221","relation":{},"ISSN":["0037-5497","1741-3133"],"issn-type":[{"value":"0037-5497","type":"print"},{"value":"1741-3133","type":"electronic"}],"subject":[],"published":{"date-parts":[[2014,7,3]]}}}