• DocumentCode
    3219543
  • Title

    Security Situation Assessment and Response Evaluation (SSARE)

  • Author

    Ambrosio, Bruce D´ ; Takikawa, Masami ; Fitzgerald, Julie ; Upper, Daniel ; Mahoney, Suzanne

  • Author_Institution
    Information Extraction & Transp. Inc., Corvallis, OR, USA
  • Volume
    1
  • fYear
    2001
  • fDate
    2001
  • Firstpage
    387
  • Abstract
    A response to cyber attack is a decision made in the face of risk and uncertainty. Uncertainty, both in our understanding of the current situation and our capacity to predict exactly the results of alternate responses, requires the ability to entertain multiple hypotheses about the actual state of system security, attacker intent, and response effects. Risk management for catastrophic or near-catastrophic breaches of security or loss of service (either through system compromise or overly aggressive response) requires the evaluation of tradeoffs among competing objectives. Security Situation Assessment and Response Evaluation (SSARE) is a mixed-initiative computer software system for wide-area cyber attack detection, situation assessment, and response evaluation. SSARE is designed to detect a large-scale attack in progress, display an assessment of the situation, and identify effective responses, including automated context and risk-sensitive policy adaptations. The core of our technical approach is (I) development of attack, attacker, mission, systems, and infrastructure element models; (2) application of IET-developed information fusion and dynamic situation assessment technology, and (3) decision-theoretic evaluation of responses
  • Keywords
    DP management; decision theory; risk management; security of data; Security Situation Assessment and Response Evaluation; attacker intent; catastrophic security breaches; cyber attack; decision-theoretic response evaluation; dynamic situation assessment technology; information fusion; mixed-initiative computer software system; near-catastrophic security breaches; response effects; risk management; service loss; system security; uncertainty; wide-area cyber attack detection; Bayesian methods; Computer architecture; Computer security; Data mining; Information security; Large-scale systems; Probability distribution; Risk management; Software systems; Uncertainty;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    DARPA Information Survivability Conference & Exposition II, 2001. DISCEX '01. Proceedings
  • Conference_Location
    Anaheim, CA
  • Print_ISBN
    0-7695-1212-7
  • Type

    conf

  • DOI
    10.1109/DISCEX.2001.932233
  • Filename
    932233