cyber security and probability problem

profileJecla8
EEGR483project11.pdf

EEGR 483 Project 1

1. Probability of success - Consider the network configuration below with three incoming attacks A1, A2, and A3; two weaknesses W1 and W2; and three controls C1, C3, C3.

For the attack to be successful any of the Attacks 1,2, or 3 must penetrate W1 and W2, and avoid controls 1,2, or 3. Assume probabilities over interval of 1 hour for attack P(A1) = .1, P(A2) =.25, P(A3) = .15. Assume probabilities of success on weakness for 1 hour as P(W1) = .7, P(W2) =.4 Assume probabilities of avoiding controls for 1 hour as P(C1) =.15, P(C2) =.1, P(C3) =.2 Compute the overall probability of success of the adversary 2. Impact Assessment Consider the simplified model for risk shown in class.

Assume the following parameters � 1 = .8/day, l 2 = .3 days , l 3 = 2 days , l 4 = .5 days Assume Time intervals T2 = 1 day, T3 = 1day. Assume assets of $ 1.1 million. a. Compute the Risk per day. b. Modify elements you as a designer might control to adjust the risk to $ .01 Million/day

A3

A2

A1

W1 W2

C1

C2

C3