Talks and Poster Presentations (without Proceedings-Entry):

E. Kiesling, A. Ekelhart, B. Grill, C. Strauss, C. Stummer:
"Multi-objective decision support for IT security control selection";
Talk: EURO INFORMS MMXIII: 26th European Conference on Operational Research, Rom; 2013-07-01 - 2013-07-04.

English abstract:
Identifying an optimal sets of security controls to protect complex information systems is a challenging problem. The aim of the research project MOSES3 is to develop and implement a framework that supports decision-makers in this task. Our approach rests upon comprehensive modeling of security knowledge, dynamic attack tree generation techniques, discrete event simulation of sophisticated attacks that exploit emergent weaknesses, and multi-objective optimization of security control portfolios. In our talk we outline the overall framework and present preliminary results

