Skip to main navigation Skip to search Skip to main content

Evolving Secure Information Systems through Attack Simulation

  • Elmar Kiesling
  • , Andreas Ekelhart
  • , Bernhard Grill
  • , Christian Stummer
  • , Christine Strauss

Publication: Chapter in book/Conference proceedingContribution to conference proceedings

Abstract

In this paper, we introduce a simulation-based, evolutionary approach for analyzing and improving the security of complex information systems. Rather than following a purely technical approach, we bring in a social and behavioral perspective through a combination of conceptual security knowledge modeling, behavioral modeling of threat agents, simulation of attacks, and evolutionary optimization. Based on results from numerous attack simulations for various internal and external attackers, metrics such as impact on confidentiality, availability, and integrity of the simulated attacks are monitored and efficient sets of security controls with respect to multiple risk, cost and benefit objectives are determined. We describe the developed approach as well as a prototypical implementation and demonstrate its applicability by means of an illustrative example.

Original languageEnglish
Title of host publicationProceedings of the 47th Annual Hawaii International Conference on System Sciences, HICSS 2014
Subtitle of host publication6–9 January 2014, Waikoloa, Hawaii
EditorsRalph H. Sprague, Jr.
Place of PublicationDanvers, MA
PublisherIEEE Press
Pages4868-4877
Number of pages10
ISBN (Print)9781479925049
DOIs
Publication statusPublished - Jan 2014
Externally publishedYes
Event47th Hawaii International Conference on System Sciences, HICSS 2014 - Waikoloa, HI, United States
Duration: 6 Jan 20149 Jan 2014

Publication series

SeriesProceedings of the Annual Hawaii International Conference on System Sciences
ISSN1530-1605

Conference

Conference47th Hawaii International Conference on System Sciences, HICSS 2014
Country/TerritoryUnited States
CityWaikoloa, HI
Period6/01/149/01/14

Cite this