RORI-based countermeasure selection using the OrBAC formalism

Gustavo Gonzalez Granadillo, Malek Belhaouane, Hervé Debar, Grégoire Jacob

Research output: Contribution to journalArticlepeer-review

Abstract

Attacks against information systems have grown in sophistication and complexity, making the detection and reaction process a challenging task for security administrators. In reaction to these attacks, the definition of security policies is an effective way to protect information systems from further damages, but it requires a great expertise and knowledge. If stronger security policies can constitute powerful countermeasures, inappropriate policies, on the other hand, may result in disastrous consequences for the organization. The implementation of stronger security policies requires in many cases the evaluation and analysis of multiple countermeasures. Current research promotes the implementation of multiple countermeasures as a strategy to react over complex attacks; however, the methodology is either hardly explained or very complicated to implement. This paper introduces a well-structured approach to evaluate and select optimal countermeasures based on the return on response investment (RORI) index. An implementation of a real case study is provided at the end of the document to show the applicability of the model over a mobile money transfer service. The service, security policies and countermeasures are expressed using the OrBAC formalism.

Original languageEnglish
Pages (from-to)63-79
Number of pages17
JournalInternational Journal of Information Security
Volume13
Issue number1
DOIs
Publication statusPublished - 1 Feb 2014
Externally publishedYes

Keywords

  • Combination approach
  • Countermeasure selection
  • Impact analysis
  • OrBAC model
  • RORI index
  • Risk mitigation
  • Surface coverage

Fingerprint

Dive into the research topics of 'RORI-based countermeasure selection using the OrBAC formalism'. Together they form a unique fingerprint.

Cite this