Risk-neutral evaluation of information security investment on data centers.

Saved in:
Bibliographic Details
Title: Risk-neutral evaluation of information security investment on data centers.
Authors: Shyue-Liang Wang1 slwang@nuk.edu.tw, Jyun-Da Chen1, Paul Stirpe2 paul.stirpe@letse.com, Tzung-Pei Hong3 tphong@nuk.edu.tw
Source: Journal of Intelligent Information Systems. Jun2011, Vol. 36 Issue 3, p329-345. 17p.
Subjects: Data security, Data library security measures, Risk management in business, Security systems, Probability theory
Abstract: Based on given data center network topology and risk-neutral management, this work proposes a simple but efficient probability-based model to calculate the probability of insecurity of each protected resource and the optimal investment on each security protection device when a data center is under security breach. We present two algorithms that calculate the probability of threat and the optimal investment for data center security respectively. Based on the insecurity flow model (Moskowitz and Kang ) of analyzing security violations, we first model data center topology using two basic components, namely resources and filters, where resources represent the protected resources and filters represent the security protection devices. Four basic patterns are then identified as the building blocks for the first algorithm, called Accumulative Probability of Insecurity, to calculate the accumulative probability of realized threat (insecurity) on each resource. To calculate the optimal security investment, a risk-neutral based algorithm, called Optimal Security Investment, which maximizes the total expected net benefit is then proposed. Numerical simulations show that the proposed approach coincides with Gordon's (Gordon and Loeb, ACM Transactions on Information and Systems Security 5(4):438-457, ) single-system analytical model. In addition, numerical results on two common data center topologies are analyzed and compared to demonstrate the effectiveness of the proposed approach. The technique proposed here can be used to facilitate the analysis and design of more secured data centers. [ABSTRACT FROM AUTHOR]
Copyright of Journal of Intelligent Information Systems is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 60262229
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Risk-neutral evaluation of information security investment on data centers.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Shyue-Liang+Wang%22">Shyue-Liang Wang</searchLink><relatesTo>1</relatesTo><i> slwang@nuk.edu.tw</i><br /><searchLink fieldCode="AR" term="%22Jyun-Da+Chen%22">Jyun-Da Chen</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Paul+Stirpe%22">Paul Stirpe</searchLink><relatesTo>2</relatesTo><i> paul.stirpe@letse.com</i><br /><searchLink fieldCode="AR" term="%22Tzung-Pei+Hong%22">Tzung-Pei Hong</searchLink><relatesTo>3</relatesTo><i> tphong@nuk.edu.tw</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Journal+of+Intelligent+Information+Systems%22">Journal of Intelligent Information Systems</searchLink>. Jun2011, Vol. 36 Issue 3, p329-345. 17p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Data+security%22">Data security</searchLink><br /><searchLink fieldCode="DE" term="%22Data+library+security+measures%22">Data library security measures</searchLink><br /><searchLink fieldCode="DE" term="%22Risk+management+in+business%22">Risk management in business</searchLink><br /><searchLink fieldCode="DE" term="%22Security+systems%22">Security systems</searchLink><br /><searchLink fieldCode="DE" term="%22Probability+theory%22">Probability theory</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Based on given data center network topology and risk-neutral management, this work proposes a simple but efficient probability-based model to calculate the probability of insecurity of each protected resource and the optimal investment on each security protection device when a data center is under security breach. We present two algorithms that calculate the probability of threat and the optimal investment for data center security respectively. Based on the insecurity flow model (Moskowitz and Kang ) of analyzing security violations, we first model data center topology using two basic components, namely resources and filters, where resources represent the protected resources and filters represent the security protection devices. Four basic patterns are then identified as the building blocks for the first algorithm, called Accumulative Probability of Insecurity, to calculate the accumulative probability of realized threat (insecurity) on each resource. To calculate the optimal security investment, a risk-neutral based algorithm, called Optimal Security Investment, which maximizes the total expected net benefit is then proposed. Numerical simulations show that the proposed approach coincides with Gordon's (Gordon and Loeb, ACM Transactions on Information and Systems Security 5(4):438-457, ) single-system analytical model. In addition, numerical results on two common data center topologies are analyzed and compared to demonstrate the effectiveness of the proposed approach. The technique proposed here can be used to facilitate the analysis and design of more secured data centers. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Journal of Intelligent Information Systems is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=60262229
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s10844-009-0109-4
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 17
        StartPage: 329
    Subjects:
      – SubjectFull: Data security
        Type: general
      – SubjectFull: Data library security measures
        Type: general
      – SubjectFull: Risk management in business
        Type: general
      – SubjectFull: Security systems
        Type: general
      – SubjectFull: Probability theory
        Type: general
    Titles:
      – TitleFull: Risk-neutral evaluation of information security investment on data centers.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Shyue-Liang Wang
      – PersonEntity:
          Name:
            NameFull: Jyun-Da Chen
      – PersonEntity:
          Name:
            NameFull: Paul Stirpe
      – PersonEntity:
          Name:
            NameFull: Tzung-Pei Hong
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 06
              Text: Jun2011
              Type: published
              Y: 2011
          Identifiers:
            – Type: issn-print
              Value: 09259902
          Numbering:
            – Type: volume
              Value: 36
            – Type: issue
              Value: 3
          Titles:
            – TitleFull: Journal of Intelligent Information Systems
              Type: main
ResultId 1