Decision Model for the Security and Utility Risk Evaluation (SURE) Framework

被引:0
|
作者
Billard, Angela K. [1 ]
机构
[1] Def Sci & Technol Grp, Edinburgh, SA, Australia
关键词
Cyber security; utility; operational requirement; risk; mitigation strategy; trade off;
D O I
10.1145/3290688.3290694
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The Security and Utility Risk Evaluation (SURE) framework is a framework for specifying and calculating risk to enable dynamic and autonomous decisions about cyber security and utility risk in generic computer-based systems. The SURE framework's decision model provides the ability to select between multiple alternative mitigation strategies in order to optimise security and utility risk during the operation of a system. This paper presents the decision model of the SURE framework and an example illustrating how the decision model operates in a mobile networking scenario. The example shows that the SURE framework's decision model enables a better fit than existing security decision models between the context of the requested action, security and utility requirements and the selected mitigation strategy, giving greater flexibility to both policy makers and users.
引用
收藏
页数:11
相关论文
共 50 条
  • [41] Research on Utility Evaluation of Grid Investment considering Risk Preference of Decision-Makers
    Wu, Hongliang
    Peng, Daoxin
    Wang, Ling
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2020, 2020
  • [42] An iterative mathematical decision model for cloud migration: A cost and security risk approach
    Shirvani, Mirsaeid Hosseini
    Rahmani, Amir Masoud
    Sahafi, Amir
    SOFTWARE-PRACTICE & EXPERIENCE, 2018, 48 (03): : 449 - 485
  • [43] The role of moral utility in decision making: An interdisciplinary framework
    Tobler, Philippe N.
    Kalis, Annemarie
    Kalenscher, Tobias
    COGNITIVE AFFECTIVE & BEHAVIORAL NEUROSCIENCE, 2008, 8 (04) : 390 - 401
  • [44] The role of moral utility in decision making: An interdisciplinary framework
    Philippe N. Tobler
    Annemarie Kalis
    Tobias Kalenscher
    Cognitive, Affective, & Behavioral Neuroscience, 2008, 8 : 390 - 401
  • [45] Approach to a Bayesian decision model for cost-benefit analysis in security risk
    Lichte, D.
    Wolf, K. -D.
    SAFETY AND RELIABILITY - SAFE SOCIETIES IN A CHANGING WORLD, 2018, : 1819 - 1826
  • [46] TOWARD AN IMPROVED DECISION FRAMEWORK FOR PUBLIC UTILITY REGULATION
    LERNER, EM
    MOAG, JS
    LAND ECONOMICS, 1968, 44 (03) : 403 - 409
  • [47] Risk Informed Decision Framework for Integrated Evaluation of Countermeasures against CBRN Threats
    Linkov, Igor
    Tkachuk, Alexander
    Canis, Laure
    Mohan, Mayank
    Keisler, Jeffrey
    JOURNAL OF HOMELAND SECURITY AND EMERGENCY MANAGEMENT, 2012, 9 (01)
  • [48] Application of Comprehensive Risk Evaluation Model in Project Invest Decision
    Xin Chun Hua
    Zhang Xing Chen
    CALL OF PAPER PROCEEDINGS OF 2008 INTERNATIONAL CONFERENCE ON MANAGEMENT SCIENCE AND ENGINEERING, 2008, : 1186 - 1190
  • [49] A Maintenance Decision-Making Model Based on Risk Evaluation
    Lv, Chuan
    Xiong, Jiayuan
    Ding, Yan
    Zhou, Haoran
    PROCEEDINGS OF 2013 INTERNATIONAL CONFERENCE ON QUALITY, RELIABILITY, RISK, MAINTENANCE, AND SAFETY ENGINEERING (QR2MSE), VOLS I-IV, 2013, : 684 - 688
  • [50] Security evaluation of the OAuth 2.0 framework
    Ferry, Eugene
    Raw, John O.
    Curran, Kevin
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (01) : 73 - 101