Selecting security control portfolios: A multi-objective simulation-optimization approach

Kiesling E, Ekelhart A, Grill B, Strauss C, Stummer C (2016)
EURO Journal on Decision Processes 4(1-2): 85-117.

Zeitschriftenaufsatz | Veröffentlicht | Englisch
 
Download
OA 2.31 MB
Autor*in
Kiesling, Elmar; Ekelhart, Andreas; Grill, Bernhard; Strauss, Christine; Stummer, ChristianUniBi
Abstract / Bemerkung
Organizations’ information infrastructures are exposed to a large variety of threats. The most complex of these threats unfold in stages, as actors exploit multiple attack vectors in a sequence of calculated steps. Deciding how to respond to such serious threats poses a challenge that is of substantial practical relevance to IT security managers. These critical decisions require an understanding of the threat actors—including their various motivations, resources, capabilities, and points of access—as well as detailed knowledge about the complex interplay of attack vectors at their disposal. In practice, however, security decisions are often made in response to acute short-term requirements, which results in inefficient resource allocations and ineffective overall threat mitigation. The decision support methodology introduced in this paper addresses this issue. By anchoring IT security managers’ decisions in an operational model of the organization’s information infrastructure, we provide the means to develop a better understanding of security problems, improve situational awareness, and bridge the gap between strategic security investment and operational implementation decisions. To this end, we combine conceptual modeling of security knowledge with a simulation-based optimization that hardens a modeled infrastructure against simulated attacks, and provide a decision support component for selecting from efficient combinations of security controls. We describe the prototypical implementation of this approach, demonstrate how it can be applied, and discuss the results of an in-depth expert evaluation.
Stichworte
IT security analysis; multi-objective portfolio selection; interactive decision support; simulation; genetic algorithm
Erscheinungsjahr
2016
Zeitschriftentitel
EURO Journal on Decision Processes
Band
4
Ausgabe
1-2
Seite(n)
85-117
ISSN
2193-9438
eISSN
2193-9446
Page URI
https://pub.uni-bielefeld.de/record/2902101

Zitieren

Kiesling E, Ekelhart A, Grill B, Strauss C, Stummer C. Selecting security control portfolios: A multi-objective simulation-optimization approach. EURO Journal on Decision Processes. 2016;4(1-2):85-117.
Kiesling, E., Ekelhart, A., Grill, B., Strauss, C., & Stummer, C. (2016). Selecting security control portfolios: A multi-objective simulation-optimization approach. EURO Journal on Decision Processes, 4(1-2), 85-117. https://doi.org/10.1007/s40070-016-0055-7
Kiesling, E., Ekelhart, A., Grill, B., Strauss, C., and Stummer, C. (2016). Selecting security control portfolios: A multi-objective simulation-optimization approach. EURO Journal on Decision Processes 4, 85-117.
Kiesling, E., et al., 2016. Selecting security control portfolios: A multi-objective simulation-optimization approach. EURO Journal on Decision Processes, 4(1-2), p 85-117.
E. Kiesling, et al., “Selecting security control portfolios: A multi-objective simulation-optimization approach”, EURO Journal on Decision Processes, vol. 4, 2016, pp. 85-117.
Kiesling, E., Ekelhart, A., Grill, B., Strauss, C., Stummer, C.: Selecting security control portfolios: A multi-objective simulation-optimization approach. EURO Journal on Decision Processes. 4, 85-117 (2016).
Kiesling, Elmar, Ekelhart, Andreas, Grill, Bernhard, Strauss, Christine, and Stummer, Christian. “Selecting security control portfolios: A multi-objective simulation-optimization approach”. EURO Journal on Decision Processes 4.1-2 (2016): 85-117.
Alle Dateien verfügbar unter der/den folgenden Lizenz(en):
Copyright Statement:
Dieses Objekt ist durch das Urheberrecht und/oder verwandte Schutzrechte geschützt. [...]
Volltext(e)
Beschreibung
Preprint des veröffentlichten Artikels
Access Level
OA Open Access
Zuletzt Hochgeladen
2021-05-03T09:09:26Z
MD5 Prüfsumme
58134b5fcb9aaa0f9d7d5a0380d63caf

Export

Markieren/ Markierung löschen
Markierte Publikationen

Open Data PUB

Web of Science

Dieser Datensatz im Web of Science®

Suchen in

Google Scholar