Sciweavers

IEEEARES
2006
IEEE

Defense trees for economic evaluation of security investments

13 years 10 months ago
Defense trees for economic evaluation of security investments
In this paper we present a mixed qualitative and quantitative approach for evaluation of Information Technology (IT) security investments. For this purpose, we model security scenarios by using defense trees, an extension of attack trees with attack countermeasures and we use economic quantitative indexes for computing the defender’s return on security investment and the attacker’s return on attack. We show how our approach can be used to evaluate effectiveness and economic profitability of countermeasures as well as their deterrent effect on attackers, thus providing decision makers with a useful tool for performing better evaluation of IT security investments during the risk management process.
Stefano Bistarelli, Fabio Fioravanti, Pamela Peret
Added 11 Jun 2010
Updated 11 Jun 2010
Type Conference
Year 2006
Where IEEEARES
Authors Stefano Bistarelli, Fabio Fioravanti, Pamela Peretti
Comments (0)