Towards dynamic risk management: success likelihood of ongoing attacks - Ecole Nationale d'Ingénieurs de Brest Accéder directement au contenu
Article Dans Une Revue Bell Labs Technical Journal Année : 2012

Towards dynamic risk management: success likelihood of ongoing attacks

Résumé

The proliferation of sophisticated cyberattacks, coupled with the steady growth of information and communication technology (ICT) systems in size and complexity, provides motivation for continuous improvements in security management. For day-to-day operation, security officers and administrators need an effective response (or decision aid) system to handle ongoing cyberattacks. Effective countermeasures must minimize the risks induced by these attacks, noting that the risk is evaluated as a function of the success likelihood and the impact of an attack. In this paper, we demonstrate how to dynamically calculate the success likelihood (SL) for an ongoing attack by considering the progress of an attacker towards his objective. Afterwards, we present a response/decision aid system based on the SL metric. Finally, we present the Success Likelihood Assessment Module (SLAM), which implements and highlights the relevance of our work for real time security management. This paper focuses on the operational aspects of a security by design approach.
Fichier non déposé

Dates et versions

hal-01162076 , version 1 (09-06-2015)

Identifiants

  • HAL Id : hal-01162076 , version 1

Citer

Wael Kanoun, Samuel Dubus, Serge Papillon, Nora Cuppens-Bouhlahia, Frédéric Cuppens. Towards dynamic risk management: success likelihood of ongoing attacks. Bell Labs Technical Journal, 2012, 17, pp.61 - 78. ⟨hal-01162076⟩
61 Consultations
0 Téléchargements

Partager

Gmail Facebook X LinkedIn More