@misc{BVDJx14, author = { Bowers, K.D. and Van Dijk, M.E. and Juels, A. and Oprea, A.M. and Rivest, R.L. and Triandopoulos, N. }, title = { Graph-based approach to deterring persistent security threats }, howpublished = { U.S. Patent 8,813,234. Issued August 19, 2014. }, date = { 2014-08-19 }, OPTmonth = { August 19, }, OPTyear = { 2014 }, urla = { google-patent-page }, abstract = { A processing device comprises a processor coupled to a memory and implements a graph-based approach to protection of a system comprising information technology infrastructure from a persistent security threat. Attack-escalation states of the persistent security threat are assigned to respective nodes in a graph, and defensive costs for preventing transitions between pairs of the nodes are assigned to respective edges in the graph. A minimum cut of the graph is computed, and a defensive strategy is determined based on the minimum cut. The system comprising information technology infrastructure subject to the persistent security threat is configured in accordance with the defensive strategy in order to deter the persistent security threat. }, }