Abstract
Organizations’ information infrastructures are exposed to a large variety of threats. The most complex of these threats unfold in stages, as actors exploit multiple attack vectors in a sequence of calculated steps. Deciding how to respond to such serious threats poses a challenge that is of substantial practical relevance to IT security managers. These critical decisions require an understanding of the threat actors—including their various motivations, resources, capabilities, and points of access—as well as detailed knowledge about the complex interplay of attack vectors at their disposal. In practice, however, security decisions are often made in response to acute short-term requirements, which results in inefficient resource allocations and ineffective overall threat mitigation. The decision support methodology introduced in this paper addresses this issue. By anchoring IT security managers’
decisions in an operational model of the organization’s information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demon-strate how it can be applied, and discuss the results of an in-depth expert evaluation.
decisions in an operational model of the organization’s information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demon-strate how it can be applied, and discuss the results of an in-depth expert evaluation.
| Original language | English |
|---|---|
| Pages (from-to) | 85-117 |
| Number of pages | 33 |
| Journal | EURO Journal on Decision Processes |
| Volume | 4 |
| Issue number | 1-2 |
| DOIs | |
| Publication status | Published - 1 Jun 2016 |
Funding
Acknowledgments The work presented in this paper has been developed within the project MOSES3, which was funded by the Austrian Science Fund (FWF) under grant P23122-N23. The research was carried out at Secure Business Austria, a COMET K1 program competence center supported by the Austrian Research Promotion Agency (FFG). Computational results have been achieved using the Vienna Scientific Cluster (VSC).
Austrian Fields of Science 2012
- 101015 Operations research
- 102016 IT security
- 502050 Business informatics
- 102009 Computer simulation
Fingerprint
Dive into the research topics of 'Selecting security control portfolios: a multi-objective simulation-optimization approach'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver