@inproceedings{1c6a111e7fa0433cbaf9acdc8a4bbc8a,
title = "Mission-oriented security model, incorporating security risk, cost and payout",
abstract = "One of the most difficult challenges facing network operators is to estimate risk and allocate resources in adversarial environments. Failure to properly allocate resources leads to failed activities, poor utilization, and insecure environments. In this paper, we explore an optimization-based approach to allocating resources called a mission-oriented security model. This model integrates security risk, cost and payout metrics to optimally allocate constrained secure resources to discrete actions called missions. We model this operation as a Mixed Integer Linear Program (MILP) which can be solved efficiently by different optimization solvers such as MATLAB MILP solver, IBM-CPLEX optimizer or CVX solver. We further introduce and explore a novel method to evaluate security risk in resource planning using two datasets—the Ponemon Institute cost of breach survey and CSI/FBI surveys of security events. Data driven simulations are used to validate the model robustness and uncover a number of insights on the importance of risk valuation in resource allocation.",
author = "Sayed, {Sayed M.} and {La Porta}, Tom and Trent Jaeger and Celik, {Z. Berkay} and Patrick McDaniel",
note = "Funding Information: Research was sponsored by the Army Research Laboratory and was accomplished under Cooperative Agreement Number W911NF-13-2-0045 (ARL Cyber Security CRA). The views and conclusions contained in this document are those of the authors and should not be interpreted as representing the official policies, either expressed or implied, of the Army Research Laboratory or the U.S. Government. The U.S. Government is authorized to reproduce and distribute reprints for Government purposes notwithstanding any copyright notation herein. Publisher Copyright: {\textcopyright} ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2018.; 14th International EAI Conference on Security and Privacy in Communication Networks, SecureComm 2018 ; Conference date: 08-08-2018 Through 10-08-2018",
year = "2018",
doi = "10.1007/978-3-030-01704-0_11",
language = "English (US)",
isbn = "9783030017033",
series = "Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST",
publisher = "Springer Verlag",
pages = "192--212",
editor = "Bing Chang and Yingjiu Li and Raheem Beyah and Sencun Zhu",
booktitle = "Security and Privacy in Communication Networks - 14th International Conference, SecureComm 2018, Proceedings",
address = "Germany",
}