Security management requires quantitative security metrics in order to effectively distribute limited resources and justify investments into security. The problem is not only to select the right security metrics but also to be sure that the selected metrics correctly represent security strength. In this paper, we tackle the problem of formal analysis of different quantitative security metrics. We consider a formal model which is based on interactions between an attacker and a system. We use this model in order to define security metrics and defensive actions which supposed to improve security strength of a system. We exploit these definitions to analyse whether security metrics are able to indicate security improvements correctly.

Formal Analysis of Security Metrics with Defensive Actions

Leanid Krautsevich;Fabio Martinelli;Artsiom Yautsiukhin
2013

Abstract

Security management requires quantitative security metrics in order to effectively distribute limited resources and justify investments into security. The problem is not only to select the right security metrics but also to be sure that the selected metrics correctly represent security strength. In this paper, we tackle the problem of formal analysis of different quantitative security metrics. We consider a formal model which is based on interactions between an attacker and a system. We use this model in order to define security metrics and defensive actions which supposed to improve security strength of a system. We exploit these definitions to analyse whether security metrics are able to indicate security improvements correctly.
2013
Istituto di informatica e telematica - IIT
ABAC
Access Control
attributes
policy engineering
risk
risk-benet analysis
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/254866
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact