Skip to main navigation Skip to search Skip to main content

Dynamic risk management response system to handle cyber threats

  • G. Gonzalez-Granadillo
  • , S. Dubus
  • , A. Motzek
  • , J. Garcia-Alfaro
  • , E. Alvarez
  • , M. Merialdo
  • , S. Papillon
  • , H. Debar
  • CNRS SAMOVAR UMR 5157
  • Bell Labs
  • Universität zu Lübeck
  • RHEA Group

Research output: Contribution to journalArticlepeer-review

Abstract

Appropriate response strategies against new and ongoing cyber attacks must be able to reduce risks down to acceptable levels, without sacrificing a mission for security. Existing approaches either evaluate impacts without considering missions’ negative-side effects, or are manually based on traditional risk assessments, leaving aside technical difficulties. In this paper we propose a dynamic risk management response system (DRMRS) consisting of a proactive and reactive management software aiming at evaluating threat scenarios in an automated manner, as well as anticipating the occurrence of potential attacks. We adopt a quantitative risk-aware approach that provides a comprehensive view of the threats, by considering their likelihood of success, the induced impact, the cost of the possible responses, and the negative side-effects of a response. Responses are selected and proposed to operators based on financial, operational and threat assessments. The DRMRS is applied to a real case study of a critical infrastructure with multiple threat scenarios.

Original languageEnglish
Pages (from-to)535-552
Number of pages18
JournalFuture Generation Computer Systems
Volume83
DOIs
Publication statusPublished - 1 Jun 2018
Externally publishedYes

Keywords

  • Automated response
  • Cybersecurity
  • Dynamic system
  • Graph attack
  • Risk assessment
  • Security assurance

Fingerprint

Dive into the research topics of 'Dynamic risk management response system to handle cyber threats'. Together they form a unique fingerprint.

Cite this