科技报告详细信息
Assessing the Value of Investments in Network Security Operations: A Systems Analytics Approach
Griffin, Jonathan ; Monahan, Brian ; Pym, David ; Wonham, Mike ; Yearworth, Mike
HP Development Company
关键词: modelling;    mathematics;    information security;    operations;    business value;   
RP-ID  :  HPL-2007-89
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】

Assessing the value of investments in network security operations remains a challenging problem. We suggest that an essential component of an analysis of this problem must be an account of the structure of the system/network and the services it is intended to deliver. We apply the methods of classical applied mathematics - using tools drawn from algebra, logic, probability theory, and theoretical computer science - to represent systems, services, and information flows in order to assess the value of network and security operations deployed in response to environmental threats and the requirements of business alignment. We use Monte Carlo experimentation to explore the levels of investment in, and trade-offs between, operations staff and security control devices necessary to maintain network availability of value determined by a given Service Level Agreement. We conclude that our methods deliver useful analyses and identify necessary future work required properly to integrate models of spatially distributed networks, stochastic environmental behaviour, and system value. Publication Info: Workshop on the Economics of Information Security, Carnegie Mellon University, Pittsburgh, PA,USA, June 7-8, 2007 31 Pages

【 预 览 】
附件列表
Files Size Format View
RO201804100001955LZ 433KB PDF download
  文献评价指标  
  下载次数:27次 浏览次数:44次