Modeling cybersecurity risks: Proof of concept of a holistic approach for integrated risk quantification

Diane S. Henshel, Alexander Alexeev, Mariana Goodall Cains, Jeff Rowe, Hasan Çam, Blaine Hoffman, Iulian Neamtiu · 2016

Decision-making in cyber-security is mostly ad-hoc and highly reliant on static policies, as well as human intervention. This does not fit current networks/systems, as they are highly dynamic systems where security assessments have to be performed, and decisions have to be made, automatically and in real-time. To address this problem, we propose a risk-based approach to cybersecurity decision-making. In our model, the system undergoes a continuous security risk assessment based on risk; decisions for each action are taken based on constructing a sequence of alternative actions and weighing the cost-benefit trade-offs for each alternative. We demonstrate the utility of our system on a concrete example involving protecting an SQL server from SQL injection attacks. We also discuss the challenges associated with implementing our model.

Read the paper · More papers on PaperTik