课题基金 / 基金详情

Algebra and Logic for Policy and Utility in Information Security

Algebra and Logic for Policy and Utility in Information Security
信息安全中政策和实用的代数和逻辑
批准号:
EP/K033042/1
负责人:
David Pym
金额:
$56.29万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2013
资助国家:
英国
项目状态:
已结题
起止时间:
2013 至 --

项目摘要

项目成果

David Pym的其他基金

相似基金

相关文献

中文摘要
翻译
经理、顾问和安全工程师负责为可能的大型复杂系统提供安全保障。另一方面,政策制定者和行业/商业领袖有责任确保提供服务的信息生态系统的整体可持续性和弹性,包括商业、政府、情报、军事和科学领域的服务。尽管在侧重点和范围上有这些差异,但两组都必须做出结合了广泛的相互竞争的、通常是相互矛盾的担忧的安全策略设计决策。考虑到这一范围的利益相关者,我们的动机是以下密切相关的问题:对于给定的系统,给定的一组利益相关者在给定的业务和威胁环境中运行,我们如何确定什么是适当的(即,有效的、负担得起的)安全策略?在什么情况下,应该保护哪些属性,保护到什么程度?对业务运营的影响是可以接受的,财务成本是多少?如果这种分析是可实现的和强有力的,它将依赖于对系统及其运作提供严格的经济和数学模型。我们如何对政策进行表述和推理,才能理解它们相对于预期安全结果的有效性,以及它们对利益相关者和企业运营的影响?我们的假设得到了广泛的背景工作和工业环境中的经验以及广泛的背景数学工作的支持,即逻辑的建模技术与数理经济学的建模技术相结合将提供一个适当的框架。我们的目标是为系统安全建模技术建立数学基础,该技术能够处理系统的结构方面、环境的随机行为,特别是安全策略及其有效性的效用理论表示。这一理论的发展提出了重大挑战。我们需要重建效用理论,以利用理论计算机科学中常见的过程数学模型所提供的对行为的复杂描述。理论计算机科学的另一种技术,Hennessy-Milner逻辑,提供了对过程行为的逻辑表征;这将需要得到加强,以便能够规范涉及效用和博弈论概念的性质,如帕累托最优和均衡性质。这一新数学的发展必须始终由政策决策应用程序驱动和指导,我们必须探索如何扩展和推广以前工作中使用的方法,以利用这一新数学。
英文摘要
Managers, consultants, and security engineers have responsibility for delivering the security of possibly large, complex systems. Policy-makers and industry/business leaders, on the other hand, have responsibility for ensuring the overall sustainability and resilience of information ecosystems that deliver services, including those in commercial, governmental, intelligence, military, and scientific worlds. Despite these differences in focus and scope, both groups must make security policy design decisions that combine a wide range of competing, often contradictory concerns.Considering this range of stakeholders, we are motivated by the following closely related questions: For a given system, with a given set of stakeholders operating in given business and threat environments, how do we determine what is an appropriate (i.e., effective, affordable) security policy? What attributes should be protected, to what extent, in what circumstances? What impact on business operations is acceptable, and at what financial cost? Such an analysis will, if it is to be achievable and robust, be dependent on the provision of rigorous economic and mathematical models of systems and their operations. How are we to express and reason about policies so that their effectiveness against the desired security outcomes and their impact upon the stakeholders and business operations can be understood?Our hypothesis, supported both by extensive background work and experience in an industrial setting and by extensive background mathematical work, is that a marriage of the modelling techniques of logic with those of mathematical economics will provide an appropriate framework. We aim to establish a mathematical basis for a systems security modelling technology that is able to handle the structural aspects of systems, the stochastic behaviour of their environments and, specifically, a utility-theoretic representation of security policies and their effectiveness.The development of this theory poses significant challenges. We need to reconstruct utility theory to take advantage of the sophisticated account of actions provided by the mathematical models of processes common in theoretical computer science. Another technique of theoretical computer science, Hennessy-Milner logic, provides a logical characterization of process behaviour; this will need to be enhanced to enable specification of properties involving utility- and game-theoretic concepts, such as Pareto optimality and equilibrium properties. The development of this novel mathematics must be driven and guided throughout by the policy decision-making applications, and we must explore how the methodology used in previous work can be extended and generalised to take advantage of this new mathematics.
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
Improving Security Policy Decisions with Models
使用模型改进安全策略决策
DOI: 10.1109/msp.2015.97
发表时间: 2015
期刊: IEEE Security & Privacy
影响因子: 1.9
作者: [Caulfield T]
通讯作者: Caulfield T
Compositional Security Modelling: Structure, Economics, and Behaviour
组合安全建模:结构、经济学和行为
DOI: --
发表时间: 2014
期刊:
影响因子: --
作者: [Caulfield, Tristan]
通讯作者: Caulfield, Tristan
A substructural logic for layered graphs
分层图的子结构逻辑
DOI: 10.1093/logcom/exu002
发表时间: 2014
期刊: Journal of Logic and Computation
影响因子: 0.7
作者: [Collinson M]
通讯作者: Collinson M
DOI: 10.1093/logcom/exz018
发表时间: 2019
期刊: Journal of Logic and Computation
影响因子: 0.7
作者: [Collinson M]
通讯作者: Collinson M
共 9 条
    A coalgebraic framework for reductive logic and proof-search (ReLiC)
    • 批准号:
      EP/S013008/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $124.23万
    • 财政年份:
      2018
    • 负责人:
      David Pym
    • 依托单位:
    Interface reasoning for interacting systems (IRIS).
    • 批准号:
      EP/R006865/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $783.13万
    • 财政年份:
      2018
    • 负责人:
      David Pym
    • 依托单位:
    Trust Domains - A framework for modelling and designing e-service infrastructures for controlled sharing of information
    • 批准号:
      TS/I002502/2
    • 项目类别:
      Research Grant
    • 资助金额:
      $3.59万
    • 财政年份:
      2013
    • 负责人:
      David Pym
    • 依托单位:
    Trust Domains - A framework for modelling and designing e-service infrastructures for controlled sharing of information
    • 批准号:
      TS/I002502/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $27.83万
    • 财政年份:
      2011
    • 负责人:
      David Pym
    • 依托单位:
    国内基金
    海外基金
    greenwashing behavior in China:Basedon an integrated view of reconfiguration of environmental authority and decoupling logic
    • 批准号:
      --
    • 项目类别:
      外国学者研究基金项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      YU BYUNGJUN
    • 依托单位:
    Incentive and governance schenism study of corporate green washing behavior in China: Based on an integiated view of econfiguration of environmental authority and decoupling logic
    • 批准号:
      --
    • 项目类别:
      外国学者研究基金项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
      YU BYUNGJUN
    • 依托单位: