Saturday, September 03, 2005

The Case for Modeling and Simulation of Information Security:

“When I hear I forget. When I see I remember. When I do, I learn.” Confucius

Abstract


A challenge that stands before the security community is to better prepare management, system administrators, and users to respond appropriately to information security crises while simultaneously reducing the anxiety associated with them. One clear approach to achieving this goal is to use modeling and simulation for education, training, and testing. This paper will present the available range of modeling and simulation capabilities in Information Assurance. It will also establish some principles for extending these capabilities into the community. It will do this by establishing a case for utilizing more simulation in our discipline, reviewing past modeling & simulation efforts within information security, reviewing the traditional types of modeling and simulation methodologies, addressing capability and experiences in computer modeling within other areas such as telecomm and economics, and providing a framework for future computer based modeling and simulation efforts in Information security.

Introduction

No comments: