3.8 Proceedings Paper

From Reactionary to Proactive Security: Context-Aware Security Policy Management and Optimization Under Uncertainty

期刊

2016 IEEE TRUSTCOM/BIGDATASE/ISPA
卷 -, 期 -, 页码 535-543

出版社

IEEE
DOI: 10.1109/TrustCom.2016.0107

关键词

-

资金

  1. New Zealand Office of Privacy Commissioner
  2. STRATUS (Security Technologies Returning Accountability, Trust and User-Centric Services in the Cloud)
  3. New Zealand Ministry of Business, Innovation and Employment

向作者/读者索取更多资源

At the core of its nature, security is a highly contextual and dynamic challenge. However, current security policy approaches are usually static, and slow to adapt to ever-changing requirements, let alone catching up with reality. In a 2012 Sophos survey, it was stated that a unique malware is created every half a second. This gives a glimpse of the unsustainable nature of a global problem; any improvement in terms of closing the time window to adapt would be a significant step forward. To exacerbate the situation, a simple change in threat and attack vector or even an implementation of the so-called bring-your-owndevice paradigm will greatly change the frequency of changed security requirements and necessary solutions required for each new context. Current security policies also typically overlook the direct and indirect costs of implementation of policies. As a result, technical teams often fail to have the ability to justify the budget to the management, from a business risk viewpoint. This paper considers both the adaptive and cost-benefit aspects of security, and introduces a novel context-aware technique for designing and implementing adaptive, optimized security policies. Our approach leverages the capabilities of stochastic programming models to optimize security policy planning, and our preliminary results demonstrate a promising step towards proactive, context-aware security policies.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

3.8
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据