Evaluating risk without data

Fabrizio Baiardi, Federico Tonelli · Computer Fraud & Security · 2014

There is a prevailing notion that risk can be evaluated only when historical data on the occurrence of some events is available. For example, the insurance rate for a car driver is a function of the probability that he/she is involved in an accident. In turn, this probability is computed according to historical data. The relation between risk and historical data immediately implies that no assessment is possible if no data is available. Data to evaluate the risk posed by an ICT system can be produced by a Monte Carlo approach that runs multiple computer simulations to assess a system before its deployment. Haruspex is a suite of tools to model the target system and the agents that implement the attack, and focuses on intelligent, goal-oriented agents. Fabrizio Baiardi and Federico Tonelli of Universita di Pisa describe how the tools build the models in such a way that the risk posed by a system can be evaluated even before it is built.

Read the paper · More papers on PaperTik