Dynamic risk management response system to handle cyber threats - Archive ouverte HAL Accéder directement au contenu
Article Dans Une Revue Future Generation Computer Systems Année : 2018

Dynamic risk management response system to handle cyber threats

Matteo Merialdo
  • Fonction : Auteur

Résumé

Appropriate response strategies against new and ongoing cyber attacks must be able to reduce risks down to acceptable levels, without sacrificing a mission for security. Existing approaches either evaluate impacts without considering missions' negative-side effects, or are manually based on traditional risk assessments, leaving aside technical difficulties. In this paper we propose a dynamic risk management response system (DRMRS) consisting of a proactive and reactive management software aiming at evaluating threat scenarios in an automated manner, as well as anticipating the occurrence of potential attacks. We adopt a quantitative risk-aware approach that provides a comprehensive view of the threats, by considering their likelihood of success, the induced impact, the cost of the possible responses, and the negative side-effects of a response. Responses are selected and proposed to operators based on financial, operational and threat assessments. The DRMRS is applied to a real case study of a critical infrastructure with multiple threat scenarios
Fichier non déposé

Dates et versions

hal-01745780 , version 1 (28-03-2018)

Identifiants

Citer

Gustavo Daniel Gonzalez Granadillo, Samuel Dubus, Alexander Motzek, Joaquin Garcia-Alfaro, Ender Yesid Alvarez Lopez, et al.. Dynamic risk management response system to handle cyber threats. Future Generation Computer Systems, 2018, 83, pp.535 - 552. ⟨10.1016/j.future.2017.05.043⟩. ⟨hal-01745780⟩
192 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More