Passer à la navigation principale Passer à la recherche Passer au contenu principal

Individual countermeasure selection based on the return on response investment index

  • Gustavo Gonzalez Granadillo
  • , Hervé Débar
  • , Grégoire Jacob
  • , Chrystel Gaber
  • , Mohammed Achemlal
  • CNRS UMR 5157 SAMOVAR
  • Orange Labs

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

As the number of attacks, and thus the number of alerts received by Security Information and Event Management Systems (SIEMs) increases, the need for appropriate treatment of these alerts has become essential. The new generation of SIEMs focuses on the response ability to automate the process of selecting and deploying countermeasures. However, current response systems select and deploy security measures without performing a comprehensive impact analysis of attacks and response scenarios. This paper addresses this limitation by proposing a model for the automated selection of optimal security countermeasures. In addition, the paper compares previous mathematical models and studies their limitations, which lead to the creation of a new model that evaluates, ranks and selects optimal countermeasures. The model relies on the optimization of cost sensitive metrics based on the Return On Response Investment (RORI) index. The optimization compares the expected impact of the attacks when doing nothing with the expected impact after applying countermeasures. A case study of a real infrastructure is deployed at the end of the document to show the applicability of the model over a Mobile Money Transfer Service.

langue originaleAnglais
titre6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012, Proceedings
EditeurSpringer Verlag
Pages156-170
Nombre de pages15
ISBN (imprimé)9783642337031
Les DOIs
étatPublié - 1 janv. 2012
Evénement6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012 - St. Petersburg, Russie
Durée: 17 oct. 201219 oct. 2012

Série de publications

NomLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume7531 LNCS
ISSN (imprimé)0302-9743
ISSN (Electronique)1611-3349

Une conférence

Une conférence6th International Conference on Mathematical Methods, Models and Architectures for Computer Network Security, MMM-ACNS 2012
Pays/TerritoireRussie
La villeSt. Petersburg
période17/10/1219/10/12

Empreinte digitale

Examiner les sujets de recherche de « Individual countermeasure selection based on the return on response investment index ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation