Matching information security vulnerabilities to organizational security profiles: a genetic algorithm approach

作者:

Highlights:

摘要

Organizations are making substantial investments in information security to reduce the risk presented by vulnerabilities in their information technology (IT) infrastructure. However, each security technology only addresses specific vulnerabilities and potentially creates additional vulnerabilities. The objective of this research is to present and evaluate a Genetic Algorithm (GA)-based approach enabling organizations to choose the minimal-cost security profile providing the maximal vulnerability coverage. This approach is compared to an enumerative approach for a given test set. The GA-based approach provides favorable results, eventually leading to improved tools for supporting information security investment decisions.

论文关键词:Information security,Genetic algorithms

论文评审过程:Available online 10 August 2004.

论文官网地址:https://doi.org/10.1016/j.dss.2004.06.004