SMART: security model adversarial risk-based tool for systems security design evaluation
Author(s) -
Paul A. Wortman,
John A. Chandy
Publication year - 2020
Publication title -
journal of cybersecurity
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.438
H-Index - 16
ISSN - 2057-2093
DOI - 10.1093/cybsec/tyaa003
Subject(s) - adversarial system , adversary , computer science , computer security , security testing , computer security model , software deployment , work (physics) , security through obscurity , risk analysis (engineering) , threat model , security service , security information and event management , cloud computing security , information security , engineering , software engineering , artificial intelligence , cloud computing , mechanical engineering , medicine , operating system
As development and deployment of secure systems continue to grow at scale, there is an equal need to evaluate these systems for vulnerabilities and other problems. However, the process of evaluating these designs is complicated and mainly proprietary to the group performing the evaluation. Generally, one follows the generic risk equation of probability and impact. In addition, one should examine the costs related to the adversary and the defender of a system. Without accounting for all of these different aspects, one cannot expect to properly assess the security of a system model or design. This work presents a security model adversarial risk-based tool (SMART) for systems security design evaluation. Our tool reads in a systems security model an attack graph and collects the necessary information for the purpose of determining the best solution based on a calculated security risk represented as a monetary amount. The advantage of the tool is the level of automation provided in the evaluation of security attack trees while providing meaningful metrics that are effortless to compare and contrast.
Accelerating Research
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom
Address
John Eccles HouseRobert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom