A Scalable Game-Theoretic Approach for Selecting Security Controls from Standardized Catalogues
This paper presents a scalable, game-theoretic approach and supporting software tool that models security control selection as a two-person zero-sum game to identify optimal, budget-constrained combinations of controls from standardized catalogues like ITSG-33, while accounting for control dependencies and attacker profiles.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are the head of security for a massive, high-tech fortress (like a military base or a bank). Your job is to protect everything inside from thieves, hackers, and saboteurs. You have a giant catalog of security measures available to you: cameras, guards, locks, alarms, firewalls, and more.
The Problem:
You can't buy everything. The catalog is huge, and your budget is limited. If you pick the wrong mix of security, you might waste money on things that don't help, or worse, leave a backdoor open for the bad guys. Traditionally, security experts try to solve this by doing complex math to guess how likely a thief is to attack. But here's the catch: You can't really know what a thief is thinking or how likely they are to succeed. It's like trying to predict the weather without a thermometer.
The Solution: A Game of Strategy
The authors of this paper, Dylan and Jason, propose a smarter way to think about this. Instead of just doing math, they suggest treating security selection like a game of chess between you (the Defender) and a hypothetical bad guy (the Attacker).
Here is how their approach works, broken down into simple steps:
1. The "Menu" of Defenses (Atomic Controls)
First, you look at your giant catalog of security controls. You pick out the ones that actually make sense for your specific fortress.
- Analogy: Imagine you are building a sandwich. You have a huge menu of ingredients. You cross off the ones that don't fit your taste or diet. You are left with a list of "applicable" ingredients (like lettuce, cheese, ham).
2. Rating the Ingredients (Effectiveness & Cost)
For every ingredient on your list, you ask two questions:
- How good is it? (Does this cheese really stop the thief? On a scale of 0 to 1, how effective is it?)
- How much does it cost? (Is this expensive imported cheese or cheap store-brand?)
- Analogy: You assign a "flavor score" and a "price tag" to every item.
3. The Rules of the Sandwich (Dependencies)
Some ingredients need others to work. You can't have "Mayo" without "Bread," or "Alarms" without "Power."
- Analogy: In the paper, they use a special algebra (a set of math rules) to make sure you don't pick a security control that requires another control you didn't pick. It's like ensuring your sandwich recipe is actually possible to make.
4. The Budget Constraint
You have a total budget (e.g., $1 million). You can't buy every delicious ingredient. You need to find the best combination that fits in your wallet.
- Analogy: This is the classic "Knapsack Problem." You have a backpack with a weight limit, and you want to pack the most valuable items possible without breaking the bag.
5. The Game: Guessing the Thief's Move
This is the most unique part. Instead of guessing probabilities (e.g., "There is a 30% chance of a hack"), you guess the Attacker's Goal.
- The Setup: You create a "Thief Profile." Maybe this thief only cares about stealing secrets (Confidentiality). Maybe they want to destroy your data (Integrity). Maybe they want to shut you down (Availability).
- The Move: You play a game where you try to pick the security combination that makes it hardest for that specific thief to win.
- The Twist: The thief is smart. They will attack the part of your fortress that is weakest. Your goal is to pick a security mix that blocks their specific path.
6. The Computer Assistant (CSAT)
Doing this math by hand for a system with hundreds of controls is impossible. It would take a human years to calculate all the combinations.
- The Tool: The authors built a software tool called CSAT (Control Selection Assistant Tool). It acts like a super-fast calculator. You feed it your list of controls, costs, and your "Thief Profile," and it instantly tells you the best security mix to buy.
The Real-World Test
To prove it works, they tested this on a fictional Canadian military system called "Ravenclaw."
- The System: It involved sensors, drones (UAVs), satellites, and databases.
- The Scale: They had about 40 optional security controls to choose from, with a budget of nearly $1 million.
- The Result: Without the tool, finding the perfect mix would have been a nightmare. With the tool, it took about 10 seconds to find the best combination for one scenario and about 17 minutes for a more complex one.
Why This Matters
- Human-Centric: It acknowledges that security is about outsmarting people, not just fixing software bugs.
- No Magic Numbers: It doesn't require you to guess impossible probabilities (like "there is a 12.4% chance of a hack"). It just asks, "If the thief wants to do X, what stops them best?"
- Scalable: It can handle huge, complex systems that would overwhelm a human analyst.
In a Nutshell:
This paper gives security teams a way to stop guessing and start strategizing. Instead of trying to predict the future, they play a game against a hypothetical thief to find the most cost-effective way to lock the doors. It turns a confusing math problem into a clear, strategic game plan.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.