arrow
返回

Optimization-Time Analysis for Cybersecurity

delete2022-07-01
delete7
PRE
AI
Y
Yunxiao Zhang *
P
Pasquale Malacaria
DOI:10.1109/TDSC.2021.3055981delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
A mathematical framework to reason about time resilience in cybersecurity is here introduced. We first consider an attacker who is able to mount several multi-stage attacks on the organization: the defender's objective is to select an optimal portfolio of security controls, within a given budget, to withstand the highest number of attacks. The mathematical model is a Markov chain with an initial state called the safe state, intermediate states for all possible attacks (each attack state denoting a probabilistic attack graph), and a sink state denoting a successful attack. The overall defence problem is formulated as a bi-level multi-objective optimization, i.e., the defender selects an optimal portfolio of security controls to mitigate an optimal attacker. In order to determine the probability of success of an attack two cases will be considered: (a) the expected probability of success and (b) the highest probability of success. We refer to these two cases as expected-time analysis and worst-case time analysis, respectively. To solve precisely these bi-level optimizations strong duality and Mixed Integer Linear Programming are used. We then extend the framework to investigate resilience in terms of the total duration of the attacks; variations of the previous optimizations are presented to this purpose. Finally numerical evaluations are provided to compare the results obtained from the expected-time analysis and the worst-case time analysis.
Keyword:
Security
Resilience
Organizations
Optimization
Markov processes
Analytical models
Mathematical model
Optimization
security
Markov processes
cyber-security
mixed integer linear programming
time resilience
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.5K
被引数:
9.6K

机构

U
university of london
学者数:
21.5W
论文数: 19.7W
被引数: 305
引用论文

引用论文

Preterm health: time to bridge the evidence gap
err2020-09-01
err0
PREAI
errRebeccah Slater; Fiona Moultrie; Ralph Bax; John van den Anker; Aomesh Bhatt
err分享
err收藏
err分享
err收藏
Cryptosporidium sp. in cultivated oysters and the natural oyster stock of the state of Maranhão, Brazil
err2023-01-01
err0
errOAAI
errCamila Moraes Silva; Anna Letícia Pinto Silva; Karinne Francisca Cardoso Watanabe; Raimunda Deusilene Barreira Porto; Danilo Cutrim Bezerra; Larissa Sarmento dos Santos Ribeiro; Viviane Correa Silva Coimbra; Hamilton Pereira Santos; Nancyleni Pinto Chaves Bezerra
err分享
err收藏
Infrastructure security games基础设施安全游戏
err2014-12-01
err48
PREAI
errBaykal-Guersoy, Melike; Duan, Zhe; Poor, H. Vincent; Garnaev, Andrey
err分享
err收藏
Dynamics and phase transitions in biased ladder systems with magnetic flux
err2019-09-01
err0
PREAI
errXin Qiao; Xiao-Bo Zhang; Ai-Xia Zhang; Zi-Fa Yu; Ju-Kui Xue
err分享
err收藏
Decision support approaches for cyber security investment网络安全投资的决策支持方法
err2016-06-01
err189
errOAAI
errFielder, Andrew; Panaousis, Emmanouil; Malacaria, Pasquale; Hankin, Chris; Smeraldi, Fabrizio
err分享
err收藏
The Donor‐Stabilized Silylene Bis[N,N′‐diisopropylbenzamidinato(−)]silicon(II): Synthesis, Electronic Structure, and Reactivity
err2014-06-05
err0
PREAI
errKonstantin Junold; Marco Nutz; Johannes A. Baus; Christian Burschka; Célia Fonseca Guerra; F. Matthias Bickelhaupt; Reinhold Tacke
err分享
err收藏
学者 查看更多内容