Using Integer Programming to Optimize Investments in Security Countermeasures: A Practical Tool for Fixed Budgets
Date of Original Version
Abstract or Description
Software engineers and businesses must make the difficult decision of how much of their budget to spend on software security mitigation for the applications and networks on which they depend. In this article, we introduce a novel method of optimizing, using Integer Programming (IP), the combination of security countermeasures to be implemented in order to maximize system security under fixed resources. We describe the steps involved in our approach, and discuss recent results with a case study client.