Modeling and Simulation in Security Evaluation

David M. Nicol · IEEE Security & Privacy · 2005

Digital computers' earliest applications evaluated models of physical systems to predict their behavior under controlled conditions. To do this, they used simulation, computing changes to the models' state variables as a function of time. Since then, simulation has become fundamental to computer science. Developments in security have their roots elsewhere, but points of contact are increasing between security and simulation, particularly in several security evaluation areas, including: 1) impact assessment for determining how security measures affect system and application performance; 2) emulation, in which real and virtual worlds are combined to study the interaction between malware and systems, and probe for new system weaknesses; 3) cyberattack exercises and training scenarios; and 4) risk assessment based on known vulnerabilities, exploits, attack capabilities, and system configuration.

Read the paper · More papers on PaperTik