• DocumentCode
    494897
  • Title

    Cost Evaluation for Intrusion Response Using Dependency Graphs

  • Author

    Kheir, Nizar ; Debar, Hervé ; Cuppens-Boulahia, Nora ; Cuppens, Frédéric ; Viinikka, Jouni

  • Author_Institution
    France Telecom R&D, Caen, France
  • fYear
    2009
  • fDate
    24-26 June 2009
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    The cost evaluation for attacks and/or responses (further called security incidents) in an IT system is a challenging issue. The high rate of service dependencies increases this challenge as the impact on a target service often spreads to its dependent services. This paper evaluates the effect of security incidents using service dependency graphs. It defines security- related properties which are used to propagate impacts in a dependency graph and thus to quantify the real cost of a security incident. The graph-based model described in this paper manages Confidentiality (C), Integrity (I) and Availability (A) propagations. It introduces matrix dependency weights in order to correlate these propagations. It also examines the effect of availability on both C and / propagations as these may exist only when the underlying components are available. This model provides common metrics for both attack and response costs evaluation. It thus enables balancing attack and response costs. An implementation of this model is proposed using CVSS base vectors. The performance of the model is measured according to the graph size and the rate of dependencies in this graph.
  • Keywords
    costing; security of data; IT system; availability; confidentiality; cost evaluation; integrity; intrusion response; security incidents; service dependency graphs; Availability; Costs; Intrusion detection; Optimal control; Protection; Research and development; Risk analysis; Security; Size measurement; Telecommunications;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Service Security, 2009. N2S '09. International Conference on
  • Conference_Location
    Paris
  • Print_ISBN
    978-2-9532-4431-1
  • Type

    conf

  • Filename
    5161653