首页> 外文会议>Critical Information Infrastructures Security; Lecture Notes in Computer Science; 4347 >Rational Choice of Security Measures Via Multi-parameter Attack Trees
【24h】

Rational Choice of Security Measures Via Multi-parameter Attack Trees

机译:通过多参数攻击树合理选择安全措施

获取原文
获取原文并翻译 | 示例

摘要

We present a simple risk-analysis based method for studying the security of institutions against rational (gain-oriented) attacks. Our method uses a certain refined form of attack-trees that are used to estimate the cost and the success probability of attacks. We use elementary game theory to decide whether the system under protection is a realistic target for gain-oriented attackers. Attacks are considered unlikely if their cost is not worth their benefits for the attackers. We also show how to decide whether the investments into security are economically justified. We outline the new method and show how it can be used in practice by going through a realistic example.
机译:我们提出了一种基于简单风险分析的方法来研究机构针对理性(以收益为导向)攻击的安全性。我们的方法使用某种特定形式的攻击树,用于估计攻击的成本和成功概率。我们使用基本博弈论来确定受保护系统是否是面向收益型攻击者的现实目标。如果攻击的代价不足以使攻击者受益,则认为攻击不太可能。我们还将展示如何确定对安全性的投资在经济上是否合理。我们通过一个现实的例子概述了这种新方法,并展示了如何在实践中使用它。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号