Skip to main content

Modeling Security Investments With Monte Carlo Simulations

Within the information security community it is almost universally agreed that the adversary has the edge when they attack our networks. This premise stems from the idea that the attacker only needs to succeed once in order to get access to an organization's sensitive information while the defender must succeed every time. This principle is a fallacy. An attacker must succeed in some way at each stage of the hacker's methodology in order to penetrate their targets. As defenders we only need to stop them at one point.

35457 (PDF, 2.63MB)

24 Sep 2014
ByDan Lyon
Share
All papers are copyrighted

No re-posting of papers is permitted