Information-Theoretic Analysis for the Efficiency of the Integrated Security Solutions
Y.-H. Choi, H.-Y. Jeong, Seung‐Woo Seo · ITC-CSCC :International Technical Conference on Circuits Systems, Computers and Communications · 2009
To protect their IT assets from security breaches, the organizations operate security solutions which can be classified into two types: proactive security solutions (PSSs) and reactive security solutions (RSSs). Measuring their efficiency is a fundamental issue in evaluating the security solutions since it makes organizations select the best configuration to maximize the level of security. Some researchers studied the effect of the integration of the PSSs and the RSSs and showed that the integration can control unwanted incidents better than a single type of security solutions. However, their studies were made mostly in a qualitative manner, not in a quantitative manner. Recently, it has been widely recognized that the quantitative analysis of the interaction of the PSSs and the RSSs can play a key role for achieving a high level of security. In this paper, we focus on deriving a quantitative model that analyzes the interactivity between the PSSs and the RSSs. Using the proposed model, we demonstrate the common belief that as vulnerabilities in an IT asset increases, the efficiency of the integrated security solutions increases, and vice versa.