
Cybersecurity refers to the practice of protecting hardware and software from cyberattacks, unauthorised access, theft, or damage and is becoming an increasing priority for organisations. A key question is the selection of measures (controls) to invest in to reduce the risk of a cybersecurity breach while keeping investments at a minimum. The contributions of this work are to (i) formulate this task as a constrained bi-objective problem, (ii) provide several realistic use cases varying in complexity for algorithm validation, and (iii) investigate the suitability of evolutionary multi-objective optimisation (in our case, MOEA/D) and an augmented epsilon-constraint approach (in CPLEX) to tackle the problem. We find that the augmented epsilon-constraint approach can solve the problem efficiently, capturing a diverse set of Pareto optimal solutions for each scenario. Although the performance of MOEA/D improves as the complexity of the problem increases, it is not able to compete with the augmented epsilon-constraint approach in terms of solutions found and reliability. We hope that the proposed problem and use cases will serve as an interesting test bed to benchmark optimisation algorithms and expand the problem formulation further.
Cybersecurity, Augmented Epsilon-constraint, Bi-objective modelling, Optimisation, MOEA/D
Cybersecurity, Augmented Epsilon-constraint, Bi-objective modelling, Optimisation, MOEA/D
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
