DocumentCode :
2383686
Title :
ACT: Attack Countermeasure Trees for Information Assurance Analysis
Author :
Roy, Arpan ; Kim, Dong Seong ; Trivedi, Kishor S.
Author_Institution :
Dept. of Electr. & Comput. Eng., Duke Univ., Durham, NC, USA
fYear :
2010
fDate :
15-19 March 2010
Firstpage :
1
Lastpage :
2
Abstract :
In modeling system response to security threats, researchers have made extensive use of state space models, notable instances including the partially observable stochastic game model proposed by Zonouz et.al. The drawback of these state space models is that they may suffer from state space explosion. Our approach in modeling defense makes use of a combinatorial model which helps avert this problem. We propose a new attack-tree (AT) model named attack-countermeasure trees (ACT) based on combinatorial modeling technique for modeling attacks and countermeasures. ACT enables one to (i) place defense mechanisms in the form of detection and mitigation techniques at any node of the tree, not just at the leaf nodes as in defense trees (DT) (ii) automate the generation of attack scenarios from the ACT using its mincuts and (iii) perform probabilistic analysis (e.g. probability of attack, attack and security investment cost, impact of an attack, system risk, return on attack (ROA) and return on investment (ROI)) in an integrated manner (iv) select an optimal countermeasure set from the pool of defense mechanisms using a method which is much less expensive compared to the state-space based approach (v) perform analysis for trees with both repeated and non-repeat events. For evaluation purposes, we suggest suitable algorithms and implement an ACT module in SHARPE. We demonstrate the utility of ACT using a practical case study (BGP attacks).
Keywords :
information analysis; security of data; stochastic games; ACT; attack countermeasure trees; combinatorial model; information assurance analysis; partially observable stochastic game model; poster abstract; probabilistic analysis; security investment cost; security threats; state space explosion; Cost function; Event detection; Explosions; Information analysis; Information security; Investments; Performance analysis; Risk analysis; State-space methods; Stochastic systems;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM IEEE Conference on Computer Communications Workshops , 2010
Conference_Location :
San Diego, CA
Print_ISBN :
978-1-4244-6739-6
Electronic_ISBN :
978-1-4244-6739-6
Type :
conf
DOI :
10.1109/INFCOMW.2010.5466633
Filename :
5466633
Link To Document :
بازگشت