Evaluation of complex security scenarios using defense trees and economic indexes. Bistarelli, S., Fabio, F., Pamela, P., & Francesco, S. JOURNAL OF EXPERIMENTAL & THEORETICAL ARTIFICIAL INTELLIGENCE, 24:161–192, 2012.
doi  abstract   bibtex   
In this article, we present a mixed qualitative and quantitative approach for evaluation of information technology (IT) security investments. For this purpose, we model security scenarios by using defense trees, an extension of attack trees with countermeasures and we use economic quantitative indexes for computing the defender's return on security investment and the attacker's return on attack. We show how our approach can be used to evaluate economic profitability of countermeasures and their deterrent effect on attackers, thus providing decision makers with a useful tool for performing better evaluation of IT security investments during the risk management process.
@article{
	11391_176498,
	author = {Bistarelli, S. and Fabio, Fioravanti and Pamela, Peretti and Francesco, Santini},
	title = {Evaluation of complex security scenarios using defense trees and economic indexes},
	year = {2012},
	journal = {JOURNAL OF EXPERIMENTAL & THEORETICAL ARTIFICIAL INTELLIGENCE},
	volume = {24},
	abstract = {In this article, we present a mixed qualitative and quantitative approach for evaluation of information technology (IT) security investments. For this purpose, we model security scenarios by using defense trees, an extension of attack trees with countermeasures and we use economic quantitative indexes for computing the defender's return on security investment and the attacker's return on attack. We show how our approach can be used to evaluate economic profitability of countermeasures and their deterrent effect on attackers, thus providing decision makers with a useful tool for performing better evaluation of IT security investments during the risk management process.},
	keywords = {security scenarios, defense tree, economic indexes, ROI; ROA},
	doi = {10.1080/13623079.2011.587206},	
	pages = {161--192}
}

Downloads: 0