• DocumentCode
    2383686
  • Title

    ACT: Attack Countermeasure Trees for Information Assurance Analysis

  • Author

    Roy, Arpan ; Kim, Dong Seong ; Trivedi, Kishor S.

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Duke Univ., Durham, NC, USA
  • fYear
    2010
  • fDate
    15-19 March 2010
  • Firstpage
    1
  • Lastpage
    2
  • Abstract
    In modeling system response to security threats, researchers have made extensive use of state space models, notable instances including the partially observable stochastic game model proposed by Zonouz et.al. The drawback of these state space models is that they may suffer from state space explosion. Our approach in modeling defense makes use of a combinatorial model which helps avert this problem. We propose a new attack-tree (AT) model named attack-countermeasure trees (ACT) based on combinatorial modeling technique for modeling attacks and countermeasures. ACT enables one to (i) place defense mechanisms in the form of detection and mitigation techniques at any node of the tree, not just at the leaf nodes as in defense trees (DT) (ii) automate the generation of attack scenarios from the ACT using its mincuts and (iii) perform probabilistic analysis (e.g. probability of attack, attack and security investment cost, impact of an attack, system risk, return on attack (ROA) and return on investment (ROI)) in an integrated manner (iv) select an optimal countermeasure set from the pool of defense mechanisms using a method which is much less expensive compared to the state-space based approach (v) perform analysis for trees with both repeated and non-repeat events. For evaluation purposes, we suggest suitable algorithms and implement an ACT module in SHARPE. We demonstrate the utility of ACT using a practical case study (BGP attacks).
  • Keywords
    information analysis; security of data; stochastic games; ACT; attack countermeasure trees; combinatorial model; information assurance analysis; partially observable stochastic game model; poster abstract; probabilistic analysis; security investment cost; security threats; state space explosion; Cost function; Event detection; Explosions; Information analysis; Information security; Investments; Performance analysis; Risk analysis; State-space methods; Stochastic systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    INFOCOM IEEE Conference on Computer Communications Workshops , 2010
  • Conference_Location
    San Diego, CA
  • Print_ISBN
    978-1-4244-6739-6
  • Electronic_ISBN
    978-1-4244-6739-6
  • Type

    conf

  • DOI
    10.1109/INFCOMW.2010.5466633
  • Filename
    5466633