Individual countermeasure selection based on the return on response investment index

  • Gustavo Gonzalez Granadillo
  • , Hervé Débar
  • , Grégoire Jacob
  • , Chrystel Gaber
  • , Mohammed Achemlal

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

As the number of attacks, and thus the number of alerts received by Security Information and Event Management Systems (SIEMs) increases, the need for appropriate treatment of these alerts has become essential. The new generation of SIEMs focuses on the response ability to automate the process of selecting and deploying countermeasures. However, current response systems select and deploy security measures without performing a comprehensive impact analysis of attacks and response scenarios. This paper addresses this limitation by proposing a model for the automated selection of optimal security countermeasures. In addition, the paper compares previous mathematical models and studies their limitations, which lead to the creation of a new model that evaluates, ranks and selects optimal countermeasures. The model relies on the optimization of cost sensitive metrics based on the Return On Response Investment (RORI) index. The optimization compares the expected impact of the attacks when doing nothing with the expected impact after applying countermeasures. A case study of a real infrastructure is deployed at the end of the document to show the applicability of the model over a Mobile Money Transfer Service.

Original languageEnglish
Title of host publication6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012, Proceedings
PublisherSpringer Verlag
Pages156-170
Number of pages15
ISBN (Print)9783642337031
DOIs
Publication statusPublished - 1 Jan 2012
Externally publishedYes
Event6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012 - St. Petersburg, Russian Federation
Duration: 17 Oct 201219 Oct 2012

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7531 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012
Country/TerritoryRussian Federation
CitySt. Petersburg
Period17/10/1219/10/12

Keywords

  • Countermeasure Selection
  • Impact Analysis
  • Mobile Money Transfer Service
  • Return On Response Investment
  • Risk Mitigation

Fingerprint

Dive into the research topics of 'Individual countermeasure selection based on the return on response investment index'. Together they form a unique fingerprint.

Cite this