2019/04/05 by Jukka Soikkeli, Soikkeli, Jukka, Luis Muñoz-González +3
Computer Science · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information and Cyber Security #Network Security and Intrusion Detection #Software-Defined Networks and 5G
paper · pdf · doi:10.48550/arxiv.1904.03082
openalex publication_date 2019/04/05 · openalex created_date 2022/07/29 · openalex updated_date 2026/07/28
The losses arising from a system being hit by cyber attacks can be\nstaggeringly high, but defending against such attacks can also be costly. This\nwork proposes an attack countermeasure selection approach based on cost impact\nanalysis that takes into account the impacts of actions by both the attacker\nand the defender. We consider a networked system providing services whose\nprovision depends on other components in the network. We model the costs and\nlosses to service availability from compromises and defensive actions to the\ncomponents, and show that while containment of the attack can be an effective\ndefensive strategy, it can be more cost-efficient to allow parts of the attack\nto continue further whilst focusing on recovering services to a functional\nstate. Based on this insight, we build a countermeasure selection method that\nchooses the most cost-effective action based on its impact on expected losses\nand costs over a given time horizon. Our method is evaluated using simulations\nin synthetic graphs representing network dependencies and vulnerabilities, and\nfound to perform well in comparison to alternatives.\n