IDEAS home Printed from https://ideas.repec.org/a/jbh/ijsrcs/v10y2024i3id1820.html

Breach and Attack Simulation Frameworks for Continuous Validation of Enterprise Security Controls

Author

Listed:
  • Adetomiwa A. Dosunmu
  • Peter Olusoji Ogundele

Abstract

Modern enterprise environments are increasingly exposed to sophisticated, persistent, and adaptive cyber threats that exploit technical vulnerabilities, misconfigurations, human weaknesses, and process failures. Traditional security validation approaches, such as periodic penetration testing, compliance audits, and vulnerability scanning, are insufficient for assessing real-world security posture in dynamic, cloud-based, and hybrid infrastructures. In response, breach and attack simulation (BAS) frameworks have emerged as a proactive and continuous approach for evaluating the effectiveness of security controls by emulating adversarial tactics, techniques, and procedures across enterprise environments. This paper provides a comprehensive review and conceptual analysis of breach and attack simulation frameworks as a mechanism for continuous security validation. Drawing exclusively on literature and industry developments, the study examines the evolution of BAS, its theoretical foundations, architectural components, simulation methodologies, integration with security operations, and its role in risk-informed decision making. The paper synthesises advances in automated attack emulation, control validation, metrics-driven assessment, and cyber resilience measurement, while highlighting challenges related to realism, scalability, false assurance, and organisational adoption. The study contributes a structured understanding of BAS frameworks and positions them as a critical capability for modern, continuously adaptive enterprise security programmes.

Suggested Citation

  • Adetomiwa A. Dosunmu & Peter Olusoji Ogundele, 2024. "Breach and Attack Simulation Frameworks for Continuous Validation of Enterprise Security Controls," International Journal of Scientific Research in Computer Science, Engineering and Information Technology, International Journal of Scientific Research in Computer Science, Engineering and Information Technology, vol. 10(3), pages 1100-1119, June.
  • Handle: RePEc:jbh:ijsrcs:v10:y2024:i3:id:1820
    DOI: 10.32628/CSEIT25113580
    Note: Article URL: https://ijsrcseit.com/home/article/view/CSEIT25113580
    as

    Download full text from publisher

    File URL: https://ijsrcseit.com/home/article/view/CSEIT25113580
    File Function: Article URL
    Download Restriction: no

    File URL: https://ijsrcseit.com/home/article/download/CSEIT25113580/CSEIT25113580
    File Function: Full text
    Download Restriction: no

    File URL: https://libkey.io/10.32628/CSEIT25113580?utm_source=ideas
    LibKey link: if access is restricted and if your library uses this service, LibKey will redirect you to where you can use your library subscription to access this item
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:jbh:ijsrcs:v10:y2024:i3:id:1820. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Pankaj Sharma (USA) (email available below). General contact details of provider: https://ijsrcseit.com/home .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.