DocumentCode
2579894
Title
Defensive dissuasion in security risk management
Author
McGill, William L.
Author_Institution
Coll. of Inf. Sci. & Technol., Pennsylvania State Univ., University Park, PA, USA
fYear
2009
fDate
11-14 Oct. 2009
Firstpage
3516
Lastpage
3521
Abstract
The purpose of this paper is to explore ways of integrating defensive dissuasion into a probabilistic framework for security risk analysis. Dissuasion influences attacker perceptions and choice with the effect of reducing the probability of occurrence for a particular course of action. Presently, few security risk analysis models offer an approach that explicitly incorporates the dissuasive effect of security in their assessments. This paper offers such an approach based on a simple model of attacker choice. This model suggests a number of alternative strategies for dissuading attackers from acting on a particular opportunity that threatens the interests of a protector. When uncertainty about the attacker is severe, this paper suggests an approach for estimating probability of attack that accounts for the dissuasive effects of countermeasures based on a worst-case attacker whose interests mirror the concerns of the protector. In addition, this paper discusses how an approach that explicitly accounts for dissuasion would enable decision makers to assess the benefits of countermeasures aimed solely at influencing attacker behavior in a manner favorable to the protector. This paper concludes by identifying directions for future research.
Keywords
probability; risk analysis; security of data; defensive dissuasion; probabilistic framework; security risk analysis model; security risk management; worst case attacker; Computer security; Cybernetics; Information security; Investments; National security; Protection; Risk analysis; Risk management; USA Councils; Uncertainty; attacker perceptions; defensive dissuasion; homeland security; security risk management; threat assessment;
fLanguage
English
Publisher
ieee
Conference_Titel
Systems, Man and Cybernetics, 2009. SMC 2009. IEEE International Conference on
Conference_Location
San Antonio, TX
ISSN
1062-922X
Print_ISBN
978-1-4244-2793-2
Electronic_ISBN
1062-922X
Type
conf
DOI
10.1109/ICSMC.2009.5346792
Filename
5346792
Link To Document