Article ID Journal Published Year Pages File Type
6882767 Computer Networks 2018 26 Pages PDF
Abstract
The number of security threats has risen sharply in recent years. This increasing trend has encouraged researchers to develop new security models in order to analyse the vulnerability of their systems, evaluating the attack and defence mechanisms, and finding the optimal security solutions. Attack Tree (AT) is the most famous security model which graphically describes the potential attack scenarios. However, it does not consider defence solutions. Hence, Defence Tree (DT) has been designed to graphically demonstrate the security solutions in order to protect the system. In this paper, we first propose a new game theory based graphical security model, Attacker-Manager Game Tree (AMGT), to consolidate all attack and defence scenarios in one model. Using this model it is easier to analyse the interactions between an attacker and security manager. Moreover, the proposed AMGT is a comprehensive educational model for system security which helps the security manager to explain the system flaws and potential risks to the higher level managers. Although finding the optimal security solutions is considered in previous studies, different definitions of optimality make finding the best solution difficult. In the rest of this paper, we consider different definitions of the optimal security solution. Afterward, the MiniMax rule is redefined to help the security manager to extract the best security solutions using AMGT based on the definition of optimality proposed by the system requirements.
Related Topics
Physical Sciences and Engineering Computer Science Computer Networks and Communications
Authors
, , , ,