Modeling cybersecurity risks: Proof of concept of a holistic approach for integrated risk quantification

2016 IEEE Symposium on Technologies for Homeland Security (HST)(2016)

引用 4|浏览2
暂无评分
摘要
Decision-making in cyber-security is mostly ad-hoc and highly reliant on static policies, as well as human intervention. This does not fit current networks/systems, as they are highly dynamic systems where security assessments have to be performed, and decisions have to be made, automatically and in real-time. To address this problem, we propose a risk-based approach to cybersecurity decision-making. In our model, the system undergoes a continuous security risk assessment based on risk; decisions for each action are taken based on constructing a sequence of alternative actions and weighing the cost-benefit trade-offs for each alternative. We demonstrate the utility of our system on a concrete example involving protecting an SQL server from SQL injection attacks. We also discuss the challenges associated with implementing our model.
更多
查看译文
关键词
risk assessment,risk calculation,cybersecurity,dynamic risk,SQL injection
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要