Combining technical and financial impacts for countermeasure selection

2Citations
Citations of this article
11Readers
Mendeley users who have this article in their library.

Abstract

Research in information security has generally focused on providing a comprehensive interpretation of threats, vulnerabilities, and attacks, in particular to evaluate their danger and prioritize responses accordingly. Most of the current approaches propose advanced techniques to detect intrusions and complex attacks but few of these approaches propose well defined methodologies to react against a given attack. In this paper, we propose a novel and systematic method to select security counter-measures from a pool of candidates, by ranking them based on the technical and financial impact associated to each alternative. The method includes industrial evaluation and simulations of the impact associated to a given security measure which allows to compute the return on response investment for different candidates. A simple case study is proposed at the end of the paper to show the applicability of the model.

Cite

CITATION STYLE

APA

Gonzalez-Granadillo, G., Ponchel, C., Blanc, G., & Debar, H. (2014). Combining technical and financial impacts for countermeasure selection. In Electronic Proceedings in Theoretical Computer Science, EPTCS (Vol. 165, pp. 1–14). Open Publishing Association. https://doi.org/10.4204/EPTCS.165.1

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free