Skip to main navigation Skip to search Skip to main content

A multi-objective decision support framework for simulation-based security control selection

  • Elmar Kiesling*
  • , Christine Strauß
  • , Christian Stummer
  • *Corresponding author for this work

Publication: Chapter in book/Conference proceedingContribution to conference proceedings

Abstract

In this paper, we report on our ongoing research on simulation-based information security risk assessment and multi-objective optimization of investment in security controls. We outline a methodological framework that accounts for characteristics of the organization, its information infrastructure, assets to be protected, the particular threat sources it faces, and the decision-makers' risk preferences. This framework comprises (i) ontological modeling of security knowledge, (ii) dynamic attack graph generation techniques, (iii) probabilistic simulation of attacks by goal-driven threat agents, (iv) meta-heuristic identification of efficient portfolios of information security controls, and (v) interactive decision support. These components facilitate novel techniques to infer possible routes of attacks and generate attack graphs based on attackers' motivation, objectives, capabilities, and available modes of entry and to use this inferred knowledge to simulate attacks on an organization's modeled infrastructure. The method supports decision makers evaluating potential security control investments in striking a balance between monetary and non-monetary criteria regarding risks, costs, and benefits. We are currently in the process of developing a prototypical implementation of the framework that will be used to evaluate the approach through application case studies.

Original languageEnglish
Title of host publicationProceedings - 2012 7th International Conference on Availability, Reliability and Security (ARES 2012)
Subtitle of host publication20-24 August 2012, Prague, Czech Republic
Place of PublicationDanvers, MA
PublisherIEEE
Pages454-462
Number of pages9
ISBN (Print)9780769547756
DOIs
Publication statusPublished - 2012
Externally publishedYes
Event2012 7th International Conference on Availability, Reliability and Security, ARES 2012 - Prague, Czech Republic
Duration: 20 Aug 201224 Aug 2012

Conference

Conference2012 7th International Conference on Availability, Reliability and Security, ARES 2012
Country/TerritoryCzech Republic
CityPrague
Period20/08/1224/08/12

Keywords

  • computational modeling
  • decision support systems
  • human factors
  • security and protection
  • simulation
  • systems analysis and design

Cite this