• DocumentCode
    2579894
  • Title

    Defensive dissuasion in security risk management

  • Author

    McGill, William L.

  • Author_Institution
    Coll. of Inf. Sci. & Technol., Pennsylvania State Univ., University Park, PA, USA
  • fYear
    2009
  • fDate
    11-14 Oct. 2009
  • Firstpage
    3516
  • Lastpage
    3521
  • Abstract
    The purpose of this paper is to explore ways of integrating defensive dissuasion into a probabilistic framework for security risk analysis. Dissuasion influences attacker perceptions and choice with the effect of reducing the probability of occurrence for a particular course of action. Presently, few security risk analysis models offer an approach that explicitly incorporates the dissuasive effect of security in their assessments. This paper offers such an approach based on a simple model of attacker choice. This model suggests a number of alternative strategies for dissuading attackers from acting on a particular opportunity that threatens the interests of a protector. When uncertainty about the attacker is severe, this paper suggests an approach for estimating probability of attack that accounts for the dissuasive effects of countermeasures based on a worst-case attacker whose interests mirror the concerns of the protector. In addition, this paper discusses how an approach that explicitly accounts for dissuasion would enable decision makers to assess the benefits of countermeasures aimed solely at influencing attacker behavior in a manner favorable to the protector. This paper concludes by identifying directions for future research.
  • Keywords
    probability; risk analysis; security of data; defensive dissuasion; probabilistic framework; security risk analysis model; security risk management; worst case attacker; Computer security; Cybernetics; Information security; Investments; National security; Protection; Risk analysis; Risk management; USA Councils; Uncertainty; attacker perceptions; defensive dissuasion; homeland security; security risk management; threat assessment;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems, Man and Cybernetics, 2009. SMC 2009. IEEE International Conference on
  • Conference_Location
    San Antonio, TX
  • ISSN
    1062-922X
  • Print_ISBN
    978-1-4244-2793-2
  • Electronic_ISBN
    1062-922X
  • Type

    conf

  • DOI
    10.1109/ICSMC.2009.5346792
  • Filename
    5346792