Search: onr:"swepub:oai:DiVA.org:kth-80665" >
Cyber Security Risk...
Cyber Security Risks Assessment with Bayesian Defense Graphs and Architectural Models
-
- Sommestad, Teodor (author)
- KTH,Industriella informations- och styrsystem
-
- Ekstedt, Mathias (author)
- KTH,Industriella informations- och styrsystem
-
- Johnson, Pontus (author)
- KTH,Industriella informations- och styrsystem
-
(creator_code:org_t)
- x, 2009
- 2009
- English.
-
In: Proceedings of the 42nd Annual Hawaii International Conference on System Sciences, HICSS. - : x. - 9780769534503
- Related links:
-
https://urn.kb.se/re...
-
show more...
-
https://doi.org/10.1...
-
show less...
Abstract
Subject headings
Close
- To facilitate rational decision making regarding cyber security investments, decision makers need to be able to assess expected losses before and after potential investments. This paper presents a model based assessment framework for analyzing the cyber security provided by different architectural scenarios. The framework uses the Bayesian statistics based Extended Influence Diagrams to express attack graphs and related countermeasures. In this paper it is demonstrated how this structure can be captured in an abstract model to support analysis based on architectural models. The approach allows calculating the probability that attacks will succeed and the expected loss of these given the instantiated architectural scenario. Moreover, the framework can handle the uncertainties that are accompanied to the analyses. In architectural analysis there are uncertainties acquainted both to the scenario and its properties, as well as to the analysis framework that stipulates how security countermeasures contribute to cyber security.
Subject headings
- TEKNIK OCH TEKNOLOGIER -- Elektroteknik och elektronik (hsv//swe)
- ENGINEERING AND TECHNOLOGY -- Electrical Engineering, Electronic Engineering, Information Engineering (hsv//eng)
Publication and Content Type
- ref (subject category)
- kon (subject category)
Find in a library
To the university's database