Selection of Pareto-efficient response plans based on financial and operational assessments

نویسندگان

  • Alexander Motzek
  • Gustavo Gonzalez Granadillo
  • Hervé Debar
  • Joaquín García
  • Ralf Möller
چکیده

Finding adequate responses to ongoing attacks on ICT systems is a pertinacious problem and requires assessments from different perpendicular viewpoints. However, current research focuses on reducing the impact of an attack irregardless of side effects caused by responses. In order to achieve a comprehensive yet accurate response to possible and ongoing attacks on a managed ICT system, we propose an approach that evaluates a response from two perpendicular perspectives: (1) A response financial impact assessment, considering the financial benefits of restoring and protecting potentially threatened operational capabilities while considering implementation and maintenance costs of responses. (2) A response operational impact assessment, which assesses potential impacts that efficient mitigation actions may inadvertently cause on the organization in an operational perspective, e.g., negative side effects of deploying mitigations. It is the key benefit of the presented approach to combine all obtained evaluations with a multi-dimensional optimization procedure such that a response plan is selected which reduces a state of risk below an admissible level while minimizing potential negative side effects of deliberately taken actions.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Fuzzy multi-criteria selection procedures in choosing data source

Technology assessment and selection has a substantial impact on organizations procedures in regards to technology transfer. Technological decisions are usually made by a group of experts, and whereby integrity of these viewpoints to a single decision can be quite complex. Today, operational databases and data warehouses exist to manage and organize data with specific features and henceforth, th...

متن کامل

Performance evaluation of forest management plans (Case study: Iranian Caspian forests)

The aim of this research was to measure the relative efficiency of forest management plans in north of Iran. In order to fulfill the research, data of 12 forest management plans were collected from the financial balance sheets of Shafaroud Forest Company during a ten years period. First of all, basic Data Envelopment Analysis (DEA) models (BCC and CCR) were used to determine the efficiency. The...

متن کامل

Tactical and operational planning for socially responsible fresh agricultural supply chain

Addressing an integrated decision-making structure for planting and harvesting scheduling may lead to more realistic, accurate, and efficient decision in fresh product supply chain. This study aims to develop an integrated bi-objective tactical and operational planning model for producing and distributing fresh crops. The first objective of the model is to maximize total revenue of supply chain...

متن کامل

Utilizing Decision Making Methods and Optimization Techniques to Develop a Model for International Facility Location Problem under Uncertainty

Abstract The purpose of this study is to consider an international facility location problem under uncertainty and present an integrated model for strategic and operational planning. The paper offers two methodologies for the location selection decision. First the extended VIKOR method for decision making problem with interval numbers is presented as a methodology for strategic evaluation of po...

متن کامل

Analysis of Response Robustness for a Multi-Objective Mathematical Model of Dynamic Cellular Manufacturing

The multi-objective optimization problem is the main purpose of generating an optimal set of targets known as Pareto optimal frontier to be provided the ultimate decision-makers. The final selection of point of Pareto frontier is usually made only based on the goals presented in the mathematical model to implement the considered system by the decision-makers. In this paper, a mathematical model...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:
  • EURASIP J. Information Security

دوره 2017  شماره 

صفحات  -

تاریخ انتشار 2017