Projects per year
Abstract
In this paper, we show a use-case of structured expert judgment to assess the risk of a cyber-security attack. We showcase the process of elicitating unknown and uncertain values using multiple experts and combining these judgments by weighing the experts based on their performance. The performance of an expert is assessed using the information and calibration score calculated from the judgments of calibration questions. The judgments are stated with three-points estimates of minimum, most likely, and maximum value, which serve as input for the PERT probability distribution. For the use-case, the input values frequency, vulnerability, and impact were asked. The combined results are propagated along an attack path to calculate the risk of a cyber-security attack. This was done using RISKEE, a tool for assessing risk in cyber-security and implementing the combination of expert judgments and propagation of the values in an attack-tree. It uses an attack graph to model the attack paths and applies probability distributions for the input values to consider the uncertainty of predictions and expert judgments. We also describe experiences and lessons-learned for conducting an expert elicitation to acquire input values for estimating risks in cyber-security.
Original language | English |
---|---|
Title of host publication | Systems, Software and Services Process Improvement - 27th European Conference, EuroSPI 2020, Proceedings |
Editors | Murat Yilmaz, Paul Clarke, Jörg Niemann, Richard Messnarz |
Publisher | Springer |
Pages | 120-134 |
Number of pages | 15 |
ISBN (Print) | 9783030564407 |
DOIs | |
Publication status | Published - 9 Aug 2020 |
Event | 27th European Conference on Systems, Software and Services Process Improvement: EuroSPI 2020 - Düsseldorf, Hybrider Event, Düsseldorf, Germany Duration: 9 Sept 2020 → 11 Sept 2020 https://2020.eurospi.net/ |
Publication series
Name | Communications in Computer and Information Science |
---|---|
Volume | 1251 CCIS |
ISSN (Print) | 1865-0929 |
ISSN (Electronic) | 1865-0937 |
Conference
Conference | 27th European Conference on Systems, Software and Services Process Improvement |
---|---|
Abbreviated title | EuroSPI 2020 |
Country/Territory | Germany |
City | Hybrider Event, Düsseldorf |
Period | 9/09/20 → 11/09/20 |
Internet address |
Keywords
- Cyber-security
- Expert elicitation
- Expert judgment
- Probabilistic methods
- Risk assessment
ASJC Scopus subject areas
- Computer Science(all)
- Mathematics(all)
- Safety, Risk, Reliability and Quality
Fields of Expertise
- Information, Communication & Computing
Treatment code (Nähere Zuordnung)
- Application
Fingerprint
Dive into the research topics of 'Assessing Risk Estimations for Cyber-Security Using Expert Judgment'. Together they form a unique fingerprint.-
Industrial Informatics
Krisper, M., Macher, G., Dobaj, J., Krug, T. & Seidl, M.
1/09/12 → …
Project: Research area
-
AH-DHYAMONT - Control platform for hydro-electric power generation
Macher, G., Krisper, M., Dobaj, J. & Krug, T.
1/01/19 → 1/02/21
Project: Research project
Activities
-
27th European Conference on System, Software, and Service Process Improvements and Innovations
Michael Krisper (Participant)
9 Sep 2020 → 11 Sep 2020Activity: Participation in or organisation of › Conference or symposium (Participation in/Organisation of)
-
Assessing Risk Estimations for Cyber-Security Using Expert Judgment
Michael Krisper (Speaker)
9 Sep 2020Activity: Talk or presentation › Talk at conference or symposium › Science to science