Title :
Assessing and Managing ICT Risk with Partial Information
Author :
Baiardi, Fabrizio ; Coro, Fabio ; Tonelli, Federico ; Bertolini, Alessandro ; Bertolotti, Roberto ; Pestonesi, Daniela
Author_Institution :
Dipt. di Inf., Univ. di Pisa, Pisa, Italy
Abstract :
Haruspex is a suite of tools to assess and manage in a probabilistic way the risk posed by an information and communication technology system. The suite is build around the application of a Monte Carlo method to a scenario where some intelligent threat agents sequentially select and compose attacks to reach their goals. Some tools of the suites build a description of a scenario with the agents, the target system, its vulnerabilities and the attacks they enable. Starting from this description, another tool applies a Monte Carlo method to simulate step by step the attacks of each agent and populate a database with samples on the attacks the agents implement, the goal they reach and the time this takes. Further tools use this database to produce statistics to assess the risk and to select countermeasures to be deployed. Since several tools of the suite require information on both the agents and the target system, we discuss how to conduct a robust assessment even when only a partial information is available. To exemplify the proposed approach, we describe the assessment of an industrial control system.
Keywords :
Monte Carlo methods; business data processing; database management systems; information technology; risk management; Haruspex; ICT risk assessment; ICT risk management; Monte Carlo method; database; industrial control system; information and communication technology system; partial information; Analytical models; Databases; Engines; Monte Carlo methods; Security; Silicon; Uncertainty; Intelligent Threat Agent; Monte Carlo Method; Probabilistic Approach; Risk Assessment;
Conference_Titel :
High Performance Computing and Communications, 2014 IEEE 6th Intl Symp on Cyberspace Safety and Security, 2014 IEEE 11th Intl Conf on Embedded Software and Syst (HPCC,CSS,ICESS), 2014 IEEE Intl Conf on
Print_ISBN :
978-1-4799-6122-1
DOI :
10.1109/HPCC.2014.198