Customized and Adaptive approach for Optimal Cybersecurity Investment
Customized and Adaptive approach for Optimal Cybersecurity Investment
批准号:
EP/R002983/1
负责人:
Chris Hankin
金额:
$49.2万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
The proposed research aims to help organisations to make better cybersecurity investments. For example is it better in a given organization to prioritise a policy of changing passwords over patching software regularly? And how frequently should passwords be changed? Should all employees scan for malware all USB sticks? The answers to these kind of questions largely depends on the type of organization and the specific threats it faces. For example while requiring employees to change passwords often may decrease the threat from some kind of attacks, it also imposes costs on the organization both in terms of help desk workload and employee productivity. Are these costs justified? it depends on the specific organization and the threats it faces.There is no one size fits all solution in cybersecurity, hence a cybersecurity investment plan should start with an appropriate model of the organization and its threat profile. We will build such a model which will capture in a formal way important aspects of the socio-human-technical characters of the organization and its exposure to attacks.This model will inform our decision support engine, which will evolve from our recent research using optimisation and game theory. In this project we will refine our existing decision support engine.One of the planned refinements is about the possible threats faced: is the attacker someone just exploring the web for weak websites or a criminal targeting that specific organization or maybe an employee from a foreign intelligence agency? The mathematical modelling of these different attackers presents challenges. Other refinements are in terms of dealing with different ways security controls can be combined, for example how to measure the effectiveness of changing password and encryption in relation to an attacker who wants to steal data - do they combine additively (i.e. are independent)? or multiplicatively (i.e. are totally correlated)?We also want our engine to be resilient, i.e. we want to give meaningful advice even if the data is not very precise, and we want it to be robust, i.e. it should provide security guarantees even when the data is not very precise. We will enrich our decision support engine with adaptivity so that once deployed it is capable to adapt to changes in the organisation, the threat profile and the general societal environment. For example the investment advice should change if a major new attack has been reported (for example the Heartbleed and Shellshock vulnerabilities in 2014), or if a new more effective security control is available.Our research will both provide theoretical and practical advances to these challenging issues. The practical advance will be in the form of prototype tools. We will measure our achievements via validation of these prototype tools. The validation will start by comparing our calculated investment strategy with expert advice and will evolve to larger case studies involving our partners and careful deployment in the field.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Improving ICS Cyber Resilience through Optimal Diversification of Network Resources
通过网络资源的优化多样化提高 ICS 网络弹性
DOI:
10.48550/arxiv.1811.00142
发表时间:
2018
期刊:
arXiv e-prints
影响因子:
--
作者:
[Li Tingting]
通讯作者:
Li Tingting
Attack Dynamics: An Automatic Attack Graph Generation Framework Based on System Topology, CAPEC, CWE, and CVE Databases
攻击动力学:基于系统拓扑、CAPEC、CWE和CVE数据库的自动攻击图生成框架
DOI:
10.1016/j.cose.2022.102938
发表时间:
2022
期刊:
Computers & Security
影响因子:
5.6
作者:
[..zdemir S..nmez F]
通讯作者:
..zdemir S..nmez F
Scalable Approach to Enhancing ICS Resilience by Network Diversity
通过网络多样性增强 ICS 弹性的可扩展方法
DOI:
10.1109/dsn48063.2020.00055
发表时间:
2020
期刊:
影响因子:
--
作者:
[Li T]
通讯作者:
Li T
Optimal security hardening over a probabilistic attack graph: a case study of an industrial control system using the CySecTool tool
概率攻击图的最佳安全强化:使用 CySecTool 工具的工业控制系统案例研究
DOI:
10.48550/arxiv.2204.11707
发表时间:
2022
期刊:
影响因子:
--
作者:
[Buczkowski P]
通讯作者:
Buczkowski P
DOI:
10.1016/j.cose.2022.102865
发表时间:
2022-08
期刊:
Comput. Secur.
影响因子:
--
作者:
[Ferda Özdemir Sönmez;Christiana C. Hankin;P. Malacaria]
通讯作者:
Ferda Özdemir Sönmez;Christiana C. Hankin;P. Malacaria
共 6 条
Research Institute in Trustworthy Inter-connected Cyber-physical Systems (RITICS)
-
批准号:EP/R022844/1
-
项目类别:Research Grant
-
资助金额:$83.97万
-
财政年份:2018
-
负责人:Chris Hankin
-
依托单位:
RITICS: Trustworthy Industrial Control Systems
-
批准号:EP/L021013/1
-
项目类别:Research Grant
-
资助金额:$96.33万
-
财政年份:2014
-
负责人:Chris Hankin
-
依托单位:
Games and Abstraction: The Science of Cyber Security
-
批准号:EP/K005790/1
-
项目类别:Research Grant
-
资助金额:$62.86万
-
财政年份:2013
-
负责人:Chris Hankin
-
依托单位:
IDEAS Factory - Detecting Terrorist Activities: Making Sense
-
批准号:EP/H023135/1
-
项目类别:Research Grant
-
资助金额:$278.43万
-
财政年份:2010
-
负责人:Chris Hankin
-
依托单位:
Monochromated Transmission Electron Microscopy
-
批准号:EP/F05677X/1
-
项目类别:Research Grant
-
资助金额:$30.6万
-
财政年份:2009
-
负责人:Chris Hankin
-
依托单位:
Aspects of Security
-
批准号:EP/H000321/1
-
项目类别:Research Grant
-
资助金额:$4.58万
-
财政年份:2009
-
负责人:Chris Hankin
-
依托单位:
Quantum Coherence: Joint Proposal for Optimising UK Research Capacity and Capability
-
批准号:EP/E036112/1
-
项目类别:Research Grant
-
资助金额:$232.33万
-
财政年份:2007
-
负责人:Chris Hankin
-
依托单位:
海外基金