{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T22:25:55Z","timestamp":1776205555312,"version":"3.50.1"},"reference-count":50,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,12,20]],"date-time":"2022-12-20T00:00:00Z","timestamp":1671494400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100008793","name":"Universidad del Rosario","doi-asserted-by":"publisher","award":["IV-TFA043"],"award-info":[{"award-number":["IV-TFA043"]}],"id":[{"id":"10.13039\/501100008793","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["BDCC"],"abstract":"<jats:p>Software is behind the technological solutions that deliver many services to our society, which means that software security should not be considered a desirable feature anymore but more of a necessity. Protection of software is an endless labor that includes the improvement of security controls but also the understanding of the sources that induce incidents, which in many cases are due to bad implementation or assumptions of controls. As traditional methods may not be efficient in detecting those security assumptions, novel alternatives must be attempted. In this sense, Security Chaos Engineering (SCE) becomes an innovative methodology based on the definition of a steady state, a hypothesis, experiments, and metrics, which allow to identify failing components and ultimately protect assets under cyber risk scenarios. As an extension of a previous work, this paper presents ChaosXploit, an SCE-powered framework that employs a knowledge database, composed of attack trees, to expose vulnerabilities that exist in a software solution that has been previously defined as a target. The use of ChaosXploit may be part of a defensive security strategy to detect and correct software misconfigurations at an early stage. Finally, different experiments are described and executed to validate the feasibility of ChaosXploit in terms of auditing the security of cloud-managed services, i.e., Amazon buckets, which may be prone to misconfigurations and, consequently, targeted by potential cyberattacks.<\/jats:p>","DOI":"10.3390\/bdcc7010001","type":"journal-article","created":{"date-parts":[[2022,12,20]],"date-time":"2022-12-20T03:56:08Z","timestamp":1671508568000},"page":"1","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["On the Way to Automatic Exploitation of Vulnerabilities and Validation of Systems Security through Security Chaos Engineering"],"prefix":"10.3390","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8962-0414","authenticated-orcid":false,"given":"Sara","family":"Palacios Chavarro","sequence":"first","affiliation":[{"name":"School of Engineering, Science and Technology, Universidad del Rosario, Bogot\u00e1 111321, D.C., Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4041-1205","authenticated-orcid":false,"given":"Pantaleone","family":"Nespoli","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7244-2631","authenticated-orcid":false,"given":"Daniel","family":"D\u00edaz-L\u00f3pez","sequence":"additional","affiliation":[{"name":"School of Engineering, Science and Technology, Universidad del Rosario, Bogot\u00e1 111321, D.C., Colombia"},{"name":"Tandon School of Engineering, New York University, Brooklyn, NY 11201, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0316-3967","authenticated-orcid":false,"given":"Yury","family":"Ni\u00f1o Roa","sequence":"additional","affiliation":[{"name":"Cloud Infrastructure Engineering, Google, Bogot\u00e1 111321, D.C., Colombia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,12,20]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez, J.I., Dur\u00e1n, S.R., D\u00edaz-L\u00f3pez, D., Pastor-Galindo, J., and M\u00e1rmol, F.G. (2020). C3-Sex: A Conversational Agent to Detect Online Sex Offenders. Electronics, 9.","DOI":"10.3390\/electronics9111779"},{"key":"ref_2","unstructured":"S\u00e1nchez, P., Huertas, A., Bovet, G., Mart\u00ednez, G., and Stille, B. (2022, January 27\u201329). An ML and Behavior Fingerprinting-based Framework for Cyberattack Detection in IoT Crowdsensing Platforms. Proceedings of the VII Jornadas Nacionales de Investigaci\u00f3n en Ciberseguridad (JNIC), Bilbao, Spain."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Botello, J.V., Mesa, A.P., Rodr\u00edguez, F.A., D\u00edaz-L\u00f3pez, D., Nespoli, P., and M\u00e1rmol, F.G. (2020). BlockSIEM: Protecting Smart City Services through a Blockchain-based and Distributed SIEM. Sensors, 20.","DOI":"10.3390\/s20164636"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"92","DOI":"10.1016\/j.cose.2014.10.004","article-title":"Managing XACML systems in distributed environments through Meta-Policies","volume":"48","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"107","DOI":"10.15332\/iteckne.v15i2.2072","article-title":"Building malware classificators usable by State security agencies","volume":"15","year":"2018","journal-title":"Iteckne"},{"key":"ref_6","unstructured":"Pastor-Galindo, J., S\u00e1ez, R., Maestre, J., Sotelo, M., G\u00f3mez, F., and Mart\u00ednez, G. (2022, January 27\u201329). Designing a platform for discovering TOR onion services. Proceedings of the VII Jornadas Nacionales de Investigaci\u00f3n en Ciberseguridad (JNIC), Bilbao, Spain."},{"key":"ref_7","unstructured":"Beyer, B., Jones, C., Petoff, J., and Murphy, N.R. (2016). Site Reliability Engineering: How Google Runs Production Systems, O\u2019Reilly Media, Inc.. [1st ed.]."},{"key":"ref_8","unstructured":"Beyer, B., Murphy, N., Rensin, D., Kawahara, K., and Thorne, S. (2018). The Site Reliability Workbook: Practical Ways to Implement SRE, O\u2019Reilly Media."},{"key":"ref_9","unstructured":"(2022, November 09). Principles of Chaos Engineering. Available online: https:\/\/principlesofchaos.org\/."},{"key":"ref_10","unstructured":"Pawlikowski, M. (2021). Chaos Engineering: Site Reliability through Controlled Disruption, Manning."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"D\u00edaz-L\u00f3pez, D., Blanco Uribe, M., Santiago Cely, C., Tarquino Murgueitio, D., Garcia Garcia, E., Nespoli, P., and G\u00f3mez M\u00e1rmol, F. (2018). Developing Secure IoT Services: A Security-Oriented Review of IoT Platforms. Symmetry, 10.","DOI":"10.3390\/sym10120669"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"109","DOI":"10.1016\/j.compeleceng.2013.11.008","article-title":"Live digital, remember digital: State of the art and research challenges","volume":"40","year":"2014","journal-title":"Comput. Electr. Eng."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"123044","DOI":"10.1109\/ACCESS.2020.3007338","article-title":"CloudStrike: Chaos Engineering for Security and Resiliency in Cloud Infrastructure","volume":"8","author":"Torkura","year":"2020","journal-title":"IEEE Access"},{"key":"ref_14","unstructured":"Palacios, S., D\u00edaz-L\u00f3pez, D., and Nespoli, P. (2022, January 27\u201329). ChaosXploit: A Security Chaos Engineering framework based on Attack Trees. Proceedings of the VII Jornadas Nacionales de Investigaci\u00f3n en Ciberseguridad (JNIC), Bilbao, Spain."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"35","DOI":"10.1109\/MS.2016.60","article-title":"Chaos Engineering","volume":"33","author":"Basiri","year":"2016","journal-title":"IEEE Softw."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Camacho, C., Ca\u00f1izares, P.C., Llana, L., and N\u00fa\u00f1ez, A. (2022). Chaos as a Software Product Line\u2014A platform for improving open hybrid-cloud systems resiliency. Software\u2014Practice and Experience, Wiley.","DOI":"10.1002\/spe.3076"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"117","DOI":"10.1016\/j.future.2021.04.001","article-title":"Observability and chaos engineering on system calls for containerized applications in Docker","volume":"122","author":"Simonsson","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Jernberg, H., Runeson, P., and Engstr\u00f6m, E. (2020, January 5\u20139). Getting started with chaos engineering\u2014Design of an implementation framework in practice. Proceedings of the ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM\u201920), Bari, Italy.","DOI":"10.1145\/3382494.3421464"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"2534","DOI":"10.1109\/TSE.2019.2954871","article-title":"A Chaos Engineering System for Live Analysis and Falsification of Exception-Handling in the JVM","volume":"47","author":"Zhang","year":"2021","journal-title":"IEEE Trans. Softw. Eng."},{"key":"ref_20","unstructured":"(2022, November 09). ChaoSlingr: Introducing Security into Chaos Testing. Available online: https:\/\/github.com\/Optum\/ChaoSlingr."},{"key":"ref_21","unstructured":"Rinehart, A., and Shortridge, K. (2021). Security Chaos Engineering Gaining Confidence in Resilience and Safety at Speed and Scale, O\u2019Reilly Media. Technical Report."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Torkura, K.A., Sukmana, M.I., Cheng, F., and Meinel, C. (2019, January 26\u201328). Security Chaos Engineering for Cloud Services: Work in Progress. Proceedings of the 2019 IEEE 18th International Symposium on Network Computing and Applications, NCA 2019, Cambridge, MA, USA.","DOI":"10.1109\/NCA.2019.8935046"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"102124","DOI":"10.1016\/j.cose.2020.102124","article-title":"Continuous auditing and threat detection in multi-cloud infrastructure","volume":"102","author":"Torkura","year":"2021","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Sharieh, S., and Ferworn, A. (2021, January 4\u20136). Securing APIs and Chaos Engineering. Proceedings of the 2021 IEEE Conference on Communications and Network Security (CNS), Tempe, AZ, USA.","DOI":"10.1109\/CNS53000.2021.9705049"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Bailey, T., Marchione, P., Swartz, P., Salih, R., Clark, M., and Denz, R. (2022, January 3\u20137). Measuring resiliency of system of systems using chaos engineering experiments. Proceedings of the 2022 SPIE 12117, Disruptive Technologies in Information Sciences VI, Orlando, FL, USA.","DOI":"10.1117\/12.2632779"},{"key":"ref_26","first-page":"117530A","article-title":"Chaos engineering experiments in middleware systems using targeted network degradation and automatic fault injection","volume":"Volume 11753","author":"Suresh","year":"2021","journal-title":"Proceedings of the Open Architecture\/Open Business Model Net-Centric Systems and Defense Transformation 2021"},{"key":"ref_27","unstructured":"(2022, March 14). The Netflix Simian Army. Available online: https:\/\/netflixtechblog.com\/the-netflix-simian-army-16e57fbab116."},{"key":"ref_28","unstructured":"(2022, November 10). Gremlin. Available online: https:\/\/www.gremlin.com\/."},{"key":"ref_29","unstructured":"(2022, November 10). Chaos Mesh. Available online: https:\/\/chaos-mesh.org\/."},{"key":"ref_30","unstructured":"(2022, November 10). Litmus. Available online: https:\/\/litmuschaos.io\/."},{"key":"ref_31","unstructured":"(2022, November 10). ChaosToolkit. Available online: https:\/\/chaostoolkit.org\/."},{"key":"ref_32","unstructured":"(2022, March 21). Chaos Engineering: The History, Principles, and Practice. Available online: https:\/\/www.gremlin.com\/community\/tutorials\/chaos-engineering-the-history-principles-and-practice\/."},{"key":"ref_33","unstructured":"(2022, March 14). UnitedHealthGroup. Available online: https:\/\/www.unitedhealthgroup.com\/."},{"key":"ref_34","unstructured":"Rosenthal, C., and Jones, N. (2020). Chaos Engineering: System Resiliency in Practice, O\u2019Reilly Media."},{"key":"ref_35","unstructured":"(2022, March 14). Verica. Available online: https:\/\/www.verica.io\/."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1361","DOI":"10.1109\/COMST.2017.2781126","article-title":"Optimal Countermeasures Selection Against Cyber Attacks: A Comprehensive Survey on Reaction Frameworks","volume":"20","author":"Nespoli","year":"2018","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Raj, S., and Walia, N.K. (2020, January 2\u20134). A Study on Metasploit Framework: A Pen-Testing Tool. Proceedings of the 2020 International Conference on Computational Performance Evaluation (ComPE), Shillong, India.","DOI":"10.1109\/ComPE49325.2020.9200028"},{"key":"ref_38","unstructured":"(2022, March 14). FOCA (Fingerprinting Organizations with Collected Archives). Available online: https:\/\/github.com\/ElevenPaths\/FOCA."},{"key":"ref_39","unstructured":"(2022, November 10). ChaosXploit. Available online: https:\/\/github.com\/SaraPalaciosCh\/ChaosXploit."},{"key":"ref_40","unstructured":"Rapid7 (2021). 2021 Cloud Misconfiguration Report, Rapid7."},{"key":"ref_41","unstructured":"Wiggers, S.J. (2022, November 10). DevOps and Cloud InfoQ Trends Report. Available online: https:\/\/www.infoq.com\/articles\/devops-and-cloud-trends-2022\/."},{"key":"ref_42","unstructured":"(2018). 2018 Cost of Data Breach Study: Impact of Business Continuity Management, Ponemon Institute LLC. Technical Report; Benchmark research sponsored by IBM."},{"key":"ref_43","unstructured":"ThougthWorks (2022, November 10). Security Chaos Engineering. Available online: https:\/\/www.thoughtworks.com\/radar\/techniques\/security-chaos-engineering."},{"key":"ref_44","unstructured":"Rinehart, A., Shortridge, K., and Safari, a.O.M.C. (2020). Security Chaos Engineering, O\u2019Reilly Media, Incorporated."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Mart\u00ednez Mart\u00ednez, I., Flori\u00e1n Quiti\u00e1n, A., D\u00edaz-L\u00f3pez, D., Nespoli, P., and G\u00f3mez M\u00e1rmol, F. (2021). MalSEIRS: Forecasting Malware Spread Based on Compartmental Models in Epidemiology. Complexity, 2021.","DOI":"10.1155\/2021\/5415724"},{"key":"ref_46","first-page":"102878","article-title":"Cyberprotection in IoT environments: A dynamic rule-based solution to defend smart devices","volume":"60","author":"Nespoli","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Ahmed, M., Panda, S., Xenakis, C., and Panaousis, E. (2022, January 23\u201326). MITRE ATT&CK-Driven Cyber Risk Assessment. Proceedings of the 17th International Conference on Availability, Reliability and Security, Vienna, Austria.","DOI":"10.1145\/3538969.3544420"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"929","DOI":"10.1002\/sec.299","article-title":"Attack countermeasure trees (ACT): Towards unifying the constructs of attack and defense trees","volume":"5","author":"Roy","year":"2012","journal-title":"Secur. Commun. Netw."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"395","DOI":"10.1109\/TPDS.2013.211","article-title":"RRE: A Game-Theoretic Intrusion Response and Recovery Engine","volume":"25","author":"Zonouz","year":"2014","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"60971","DOI":"10.1109\/ACCESS.2021.3074021","article-title":"A Bio-Inspired Reaction Against Cyberattacks: AIS-Powered Optimal Countermeasures Selection","volume":"9","author":"Nespoli","year":"2021","journal-title":"IEEE Access"}],"container-title":["Big Data and Cognitive Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2504-2289\/7\/1\/1\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:44:28Z","timestamp":1760147068000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2504-2289\/7\/1\/1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,20]]},"references-count":50,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,3]]}},"alternative-id":["bdcc7010001"],"URL":"https:\/\/doi.org\/10.3390\/bdcc7010001","relation":{},"ISSN":["2504-2289"],"issn-type":[{"value":"2504-2289","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,20]]}}}