An Abstract Reduction Model for Computer Security Risk

Mohamed Hamdi, Noureddine A. Boudriga · 2004

This paper presents an approach for decision making under security risks in a computer network environment. The proposed method relies on a many sorted algebraic signature and on a rewriting system. This latter is shown to be terminating and yielding a normal form, called the risk analysis equation, that models the cost-benefit balance. Furthermore, a gradual algebraic resolution of the risk analysis equation is described. This formalism helps security analysts to automate the selection of the optimal security solutions that minimize the residual risk.

Read the paper · More papers on PaperTik