Strategic games on defense trees

  • Authors:
  • Stefano Bistarelli;Marco Dall'Aglio;Pamela Peretti

  • Affiliations:
  • Dipartimento di Scienze, Università degli Studi "G. d'Annunzio", Pescara, Italy and Istituto di Informatica e Telematica, CNR, Pisa, Italy;Dipartimento di Scienze, Università degli Studi "G. d'Annunzio", Pescara, Italy;Dipartimento di Scienze, Università degli Studi "G. d'Annunzio", Pescara, Italy

  • Venue:
  • FAST'06 Proceedings of the 4th international conference on Formal aspects in security and trust
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we use defense trees, an extension of attack trees with countermeasures, to represent attack scenarios and game theory to detect the most promising actions attacker and defender. On one side the attacker wants to break the system (with as little efforts as possible), on the opposite side the defender want to protect it (sustaining the minimum cost). As utility function for the attacker and for the defender we consider economic indexes (like the Return on Investment (ROI) and the Return on Attack (ROA)). We show how our approach can be used to evaluate effectiveness and economic profitability of countermeasures as well as their deterrent effect on attackers, thus providing decision makers with a useful tool for performing better evaluation of IT security investments during the risk management process.