A game theoretic approach to cyber security risk management

A game theoretic approach to cyber security risk management
复制标题

DOI:
10.1177/1548512917699724
复制
发表时间:
2018-04-01
影响因子:
0.8
通讯作者:
Turner, Andrew
Turner, Andrew
中科院分区:
其他
文献类型:
--
作者:
Musman, Scott;Turner, Andrew

文献摘要

被引文献

相似文献

本文介绍了网络安全游戏(CSG)。网络安全游戏是一种在软件中实现的方法,它可以定量识别网络安全风险,并使用此指标来确定任何给定投资水平的安全方法的最佳使用。网络安全游戏通过最小化其使命风险来最大限度地提高系统在当今竞争激烈的网络环境中运行的能力。通过使用使命影响模型计算网络事件的后果并将其与攻击成功的可能性相结合来计算风险评分。通过将威胁模型应用于系统拓扑模型和防御者模型来计算攻击成功的可能性。网络安全游戏考虑到网络系统的广泛互联性,防御者必须防御所有多步攻击路径,攻击者只需要一步就可以成功。它采用了一种博弈论解决方案,该解决方案使用一种博弈公式来确定防御策略,以最大限度地降低网络风险(MiniMax)。本文探讨了网络安全游戏的构建方法和模型。使用销售点系统的有限示例来提供网络安全游戏模型和分析的具体演示。
This paper describes the Cyber Security Game (CSG). Cyber Security Game is a method that has been implemented in software that quantitatively identifies cyber security risks and uses this metric to determine the optimal employment of security methods for any given investment level. Cyber Security Game maximizes a system's ability to operate in today's contested cyber environment by minimizing its mission risk. The risk score is calculated by using a mission impact model to compute the consequences of cyber incidents and combining that with the likelihood that attacks will succeed. The likelihood of attacks succeeding is computed by applying a threat model to a system topology model and defender model. Cyber Security Game takes into account the widespread interconnectedness of cyber systems, where defenders must defend all multi-step attack paths and an attacker only needs one to succeed. It employs a game theoretic solution using a game formulation that identifies defense strategies to minimize the maximum cyber risk (MiniMax). This paper discusses the methods and models that compose Cyber Security Game . A limited example of a Point of Sale system is used to provide specific demonstrations of Cyber Security Game models and analyses.