Mission?centric decision support in cybersecurity via Bayesian Privilege Attack Graph
نویسندگان
چکیده
We present an approach to decision support in cybersecurity with respect cyber threats and stakeholders' requirements. situations which experts need take actions mitigate the risks, such as temporarily putting IT system out of operation, but consult them other stakeholders. propose a that uses mission decomposition model representing organization's functional security requirements on its infrastructure. Based state assessment, is, discovery vulnerabilities attacker's position, calculates resilience metrics for each infrastructure's configuration, how likely are they not be disrupted. The calculation is enabled by two novel formal models, Privilege-Exploit Attack Graph Bayesian Privilege Graph, reduce complex attack graphs into comprehensible bipartite graph. Moreover, illustrate impact exploiting attackers gaining privileges. recommends most resilient configurations both non-technical stakeholders, who may then choose configuration apply. Our illustrated case study real-world medical information system.
منابع مشابه
Decision support for Cybersecurity risk planning
a r t i c l e i n f o Security countermeasures help ensure the confidentiality, availability, and integrity of information systems by preventing or mitigating asset losses from Cybersecurity attacks. Due to uncertainty, the financial impact of threats attacking assets is often difficult to measure quantitatively, and thus it is difficult to prescribe which countermeasures to employ. In this res...
متن کاملA Bayesian model decision support system: dryland salinity management application
Addressing environmental management problems at catchment scales requires an integrated modelling approach, in which key bio-physical and socio-economic drivers, processes and impacts are all considered. Development of Decision Support Systems (DSSs) for environmental management is rapidly progressing. This paper describes the integration of physical, ecological, and socio-economic components i...
متن کاملCybersecurity Games and Investments: A Decision Support Approach
In this paper we investigate how to optimally invest in cybersecurity controls. We are particularly interested in examining cases where the organization suffers from an underinvestment problem or inefficient spending on cybersecurity. To this end, we first model the cybersecurity environment of an organization. We then model non-cooperative cybersecurity control-games between the defender which...
متن کاملBayesian Regularization via Graph Laplacian
Regularization plays a critical role in modern statistical research, especially in high dimensional variable selection problems. Existing Bayesian methods usually assume independence between variables a priori. In this article, we propose a novel Bayesian approach, which explicitly models the dependence structure through a graph Laplacian matrix. We also generalize the graph Laplacian to allow ...
متن کاملa bayesian model decision support system: dryland salinity management application
addressing environmental management problems at catchment scales requires an integrated modelling approach, in which key bio-physical and socio-economic drivers, processes and impacts are all considered. development of decision support systems (dsss) for environmental management is rapidly progressing. this paper describes the integration of physical, ecological, and socio-economic components i...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
ژورنال
عنوان ژورنال: Engineering reports
سال: 2022
ISSN: ['2577-8196']
DOI: https://doi.org/10.1002/eng2.12538