{"id":{"repo_id":"eastern-wash","oai_identifier":"oai:dc.ewu.edu:theses-1485"},"canonical_url":"https://search.dev.ndltd.org/etd/eastern-wash/oai:dc.ewu.edu:theses-1485","repository":{"repo_id":"eastern-wash","name":"Eastern Washington University","base_url":"https://dc.ewu.edu/do/oai/"},"display":{"title":"Determining vulnerability using attach graphs: an expansion of the current FAIR model","abstract":"<p>Factor Analysis of Information Risk (FAIR) provides a framework for measuring and understanding factors that contribute to information risk. One such factor is FAIR Vulnerability; the probability that an event involving a threat will result in a loss. An asset is vulnerable if a threat actor’s Threat Capability is higher than the Resistance Strength of the asset. In FAIR scenarios, Resistance Strength is currently estimated for entire assets, oversimplifying assets containing individual systems and the surrounding environment. This research explores enhancing estimations of FAIR Vulnerability by modeling interactions between threat actors and assets through attack graphs. By breaking down the scenario into more representative and quantifiable parts, more detailed and precise analyses are possible.</p>","abstract_html":"&lt;p&gt;Factor Analysis of Information Risk (FAIR) provides a framework for measuring and understanding factors that contribute to information risk. One such factor is FAIR Vulnerability; the probability that an event involving a threat will result in a loss. An asset is vulnerable if a threat actor’s Threat Capability is higher than the Resistance Strength of the asset. In FAIR scenarios, Resistance Strength is currently estimated for entire assets, oversimplifying assets containing individual systems and the surrounding environment. This research explores enhancing estimations of FAIR Vulnerability by modeling interactions between threat actors and assets through attack graphs. By breaking down the scenario into more representative and quantifiable parts, more detailed and precise analyses are possible.&lt;/p&gt;","abstract_has_math":false,"creators":["Anderson, Beth M."],"institution":null,"degree_name":"Master of Science (MS) in Computer Science","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2018,"date_issued":"2018-01-01T08:00:00Z","date_published":"2018-01-01T08:00:00Z","updated_at":"2026-07-24T02:13:29Z","subjects":["Databases and Information Systems","Information Security"],"languages":[],"rights":["Access is available to all users"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://dc.ewu.edu/theses/483","outbound_label":"Repository record","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:creator","label":"Author","values":["Anderson, Beth M."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MS) in Computer Science"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Databases and Information Systems","Information Security"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["Access is available to all users"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://dc.ewu.edu/theses/483"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["<p>Factor Analysis of Information Risk (FAIR) provides a framework for measuring and understanding factors that contribute to information risk. One such factor is FAIR Vulnerability; the probability that an event involving a threat will result in a loss. An asset is vulnerable if a threat actor’s Threat Capability is higher than the Resistance Strength of the asset. In FAIR scenarios, Resistance Strength is currently estimated for entire assets, oversimplifying assets containing individual systems and the surrounding environment. This research explores enhancing estimations of FAIR Vulnerability by modeling interactions between threat actors and assets through attack graphs. By breaking down the scenario into more representative and quantifiable parts, more detailed and precise analyses are possible.</p>"]},{"key":"dc:title","label":"Title","values":["Determining vulnerability using attach graphs: an expansion of the current FAIR model"]}]}],"canonical_facts":{"dc:creator":["Anderson, Beth M."],"dc:description.abstract":["<p>Factor Analysis of Information Risk (FAIR) provides a framework for measuring and understanding factors that contribute to information risk. One such factor is FAIR Vulnerability; the probability that an event involving a threat will result in a loss. An asset is vulnerable if a threat actor’s Threat Capability is higher than the Resistance Strength of the asset. In FAIR scenarios, Resistance Strength is currently estimated for entire assets, oversimplifying assets containing individual systems and the surrounding environment. This research explores enhancing estimations of FAIR Vulnerability by modeling interactions between threat actors and assets through attack graphs. By breaking down the scenario into more representative and quantifiable parts, more detailed and precise analyses are possible.</p>"],"dc:identifier":["https://dc.ewu.edu/theses/483"],"dc:rights":["Access is available to all users"],"dc:subject":["Databases and Information Systems","Information Security"],"dc:title":["Determining vulnerability using attach graphs: an expansion of the current FAIR model"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["Master of Science (MS) in Computer Science"]},"updated_at":"2026-07-24T02:13:29Z"}