DocumentCode
677678
Title
Simulation-based optimization of information security controls: An adversary-centric approach
Author
Kiesling, Elmar ; Strauss, Christine ; Ekelhart, Andreas ; Grill, Bernhard ; Stummer, Christian
Author_Institution
Inf. & Software Eng. Group, Vienna Univ. of Technol., Vienna, Austria
fYear
2013
fDate
8-11 Dec. 2013
Firstpage
2054
Lastpage
2065
Abstract
Today, information systems are threatened not only by the opportunistic exploitation of particular technical weaknesses, but increasingly by targeted attacks that combine multiple vectors to achieve the attacker´s objectives. Given the complexities involved, identifying the most appropriate measures to counteract the latter threats is highly challenging. In this paper, we introduce a novel simulation-optimization method that tackles this problem. It combines rich conceptual modeling of security knowledge with discrete event simulation and metaheuristic optimization techniques. By simulating attacks, the method infers possible routes of attack and identifies emergent weaknesses while accounting for adversaries´ heterogeneous objectives, capabilities, and available modes of entry. The optimization iteratively adapts the system model by means of a genetic algorithm and optimizes its ability to detect ongoing attacks and prevent their successful execution. We describe a prototypical implementation and illustrate its application by means of scenarios for five types of adversaries.
Keywords
discrete event simulation; genetic algorithms; information systems; security of data; adversary types; adversary-centric approach; attack detection; conceptual modeling; discrete event simulation; genetic algorithm; information security controls; information systems; metaheuristic optimization techniques; simulation-based optimization; simulation-optimization method; Abstracts; Context; Context modeling; Information systems; Optimization; Organizations; Security;
fLanguage
English
Publisher
ieee
Conference_Titel
Simulation Conference (WSC), 2013 Winter
Conference_Location
Washington, DC
Print_ISBN
978-1-4799-2077-8
Type
conf
DOI
10.1109/WSC.2013.6721583
Filename
6721583
Link To Document