首页> 外文期刊>EURO Journal on Decision Processes >Selecting security control portfolios: a multi-objective simulation-optimization approach
【24h】

Selecting security control portfolios: a multi-objective simulation-optimization approach

机译:选择安全控制产品组合:一种多目标仿真优化方法

获取原文
获取原文并翻译 | 示例
           

摘要

Organizations' information infrastructures are exposed to a large variety of threats. The most complex of these threats unfold in stages, as actors exploit multiple attack vectors in a sequence of calculated steps. Deciding how to respond to such serious threats poses a challenge that is of substantial practical relevance to IT security managers. These critical decisions require an understanding of the threat actors-including their various motivations, resources, capabilities, and points of access-as well as detailed knowledge about the complex interplay of attack vectors at their disposal. In practice, however, security decisions are often made in response to acute short-term requirements, which results in inefficient resource allocations and ineffective overall threat mitigation. The decision support methodology introduced in this paper addresses this issue. By anchoring IT security managers' decisions in an operational model of the organization's information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demonstrate how it can be applied, and discuss the results of an in-depth expert evaluation.
机译:组织的信息基础架构面临各种各样的威胁。随着行动者在一系列计算步骤中利用多种攻击媒介,这些威胁中最复杂的阶段将逐步展开。确定如何应对此类严重威胁提出了一个挑战,与IT安全经理有着实质性的实际联系。这些关键决策需要了解威胁行为者(包括其各种动机,资源,能力和访问点),以及有关可利用的攻击媒介复杂相互作用的详细知识。但是,实际上,安全决策通常是针对紧急的短期需求而做出的,这导致资源分配效率低下和总体威胁缓解效率低下。本文介绍的决策支持方法论解决了这个问题。通过将IT安全经理的决策锚定在组织的信息基础架构的运营模型中,我们提供了一种手段,可以使人们更好地理解安全问题,提高态势感知并弥合战略安全投资与运营实施决策之间的鸿沟。为此,我们将安全知识的概念建模与基于仿真的优化相结合,以优化建模基础设施以抵御仿真攻击,并提供决策支持组件,以从安全控制的有效组合中进行选择。我们描述了这种方法的原型实现,演示了如何应用它,并讨论了深入专家评估的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号