Attack Countermeasure Trees: A Non-state-space Approach Towards Analyzing Security and Finding Optimal Countermeasure Set
dc.contributor.advisor | Trivedi, Kishor S | |
dc.contributor.author | Roy, Arpan | |
dc.date.accessioned | 2011-01-06T20:46:03Z | |
dc.date.available | 2011-01-06T20:46:03Z | |
dc.date.issued | 2010 | |
dc.department | Electrical and Computer Engineering | |
dc.description.abstract | Attack tree (AT) is one of the widely used non-statespace models in security analysis. The basic formalism of AT does not take into account defense mechanisms. Defense trees (DTs) have been developed to investigate the effect of defense mechanisms usinghg measures such as attack cost, security investment cost, return on attack (ROA) and return on investment (ROI). DT, however, places defense mechanisms only at the leaf nodes and the corresponding ROI/ROA analysis does not incorporate the probabilities of attack. In attack response tree (ART), attack and response are both captured but ART suffers from the problem of state-space explosion, since solution of ART is obtained by means of a state space model. In this paper, we present a novel attack tree paradigm called attack countermeasure tree (ACT) which avoids the generation and solution of the state-space model and takes into account attacks as well as countermeasures (in the form of detection and mitigation events). In ACT, detection and mitigation are allowed not just at the leaf node but also at the intermediate nodes while at the same time the state-space explosion problem is avoided in its analysis. We use single and multiobjective optimization to find optimal countermeasures under different constraints. We illustrate the features of ACT using several case studies. | |
dc.identifier.uri | ||
dc.subject | Electrical engineering | |
dc.subject | Computer engineering | |
dc.subject | Computer science | |
dc.subject | attack countermeasure trees | |
dc.subject | mincuts | |
dc.subject | non-state-space model | |
dc.subject | Optimization | |
dc.subject | return on investment | |
dc.title | Attack Countermeasure Trees: A Non-state-space Approach Towards Analyzing Security and Finding Optimal Countermeasure Set | |
dc.type | Master's thesis |