Considering technical and financial impact in the selection of security countermeasures against Advanced Persistent Threats (APTs)

  • Gustavo Gonzalez Granadillo
  • , Joaquin Garcia-Alfaro
  • , Herve Debar
  • , Christophe Ponchel
  • , Laura Rodriguez Martin

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper presents a model to evaluate and select security countermeasures from a pool of candidates. The model performs industrial evaluation and simulations of the financial and technical impact associated to security countermeasures. The financial impact approach uses the Return On Response Investment (RORI) index to compare the expected impact of the attack when no response is enacted against the impact after applying security countermeasures. The technical impact approach evaluates the protection level against a threat, in terms of confidentiality, integrity, and availability. We provide a use case on malware attacks that shows the applicability of our model in selecting the best countermeasure against an Advanced Persistent Threat.

Original languageEnglish
Title of host publication2015 7th International Conference on New Technologies, Mobility and Security - Proceedings of NTMS 2015 Conference and Workshops
EditorsMohamad Badra, Azzedine Boukerche, Pascal Urien, Azzedine Boukerche
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781479987849
DOIs
Publication statusPublished - 14 Sept 2015
Externally publishedYes
Event7th International Conference on New Technologies, Mobility and Security, NTMS 2015 - Paris, France
Duration: 27 Jul 201529 Jul 2015

Publication series

Name2015 7th International Conference on New Technologies, Mobility and Security - Proceedings of NTMS 2015 Conference and Workshops

Conference

Conference7th International Conference on New Technologies, Mobility and Security, NTMS 2015
Country/TerritoryFrance
CityParis
Period27/07/1529/07/15

Keywords

  • Investment
  • Malware
  • Mathematical model
  • Measurement
  • Organizations
  • Risk management

Fingerprint

Dive into the research topics of 'Considering technical and financial impact in the selection of security countermeasures against Advanced Persistent Threats (APTs)'. Together they form a unique fingerprint.

Cite this