Using Integer Programming to Optimize Investments in Security Countermeasures: A Practical Tool for Fixed Budgets

Date of Original Version



Working Paper

Abstract or Description

Software engineers and businesses must make the difficult decision of how much of their budget to spend on software security mitigation for the applications and networks on which they depend. In this article, we introduce a novel method of optimizing, using Integer Programming (IP), the combination of security countermeasures to be implemented in order to maximize system security under fixed resources. We describe the steps involved in our approach, and discuss recent results with a case study client.