Otimização de Investimentos em Cibersegurança Sob Restrições Orçamentárias

Resumo


Controles de cibersegurança competem por orçamentos organizacionais limitados. Este artigo formula sua seleção como um Problema da Mochila 0/1, combinando custo de implementação, eficácia, impacto operacional, criticidade dos ativos e cobertura MITRE ATT&CK derivada dos CIS Controls v8. O modelo binário é convertido em QUBO e, depois, em um Hamiltoniano de custo Ising com penalidade orçamentária e variáveis de folga. A contribuição fornece uma formulação comum para otimização clássica e futuras avaliações com QAOA, sem pressupor vantagem quântica.
Palavras-chave: Cibersegurança, Otimização Combinatória, Controles de Segurança, QUBO, QAOA

Referências

Al Salek, A., Padyab, A., Lundgren, M., e Åhlfeldt, R.-M. (2026). A taxonomy of cybersecurity economic models. Computers & Security. In press.

Bucher, D., Stein, J., Feld, S., e Linnhoff-Popien, C. (2025). Penalty-free approach to accelerating constrained quantum optimization. Physical Review A, 112(6):062605.

Center for Internet Security (2021). CIS Controls Version 8. [link].

Christiansen, P., Binkowski, L., Ramacciotti, D., e Wilkening, S. (2025). Quantum tree generator improves QAOA state-of-the-art for the knapsack problem. In Culhane, C., Byrd, G., Muller, H., Delgado, A., e Eidenbenz, S., editors, 2025 IEEE International Conference on Quantum Computing and Engineering (QCE). IEEE.

Farhi, E., Goldstone, J., e Gutmann, S. (2014). A quantum approximate optimization algorithm. arXiv:1411.4028 [quant-ph].

Fielder, A., Panaousis, E., Malacaria, P., Hankin, C., e Smeraldi, F. (2016). Decision support approaches for cyber security investment. Decision Support Systems, 86:13–23.

Giraldo-Osorio, A., Navarrete, A., Griol, D., e Calvo-Manzano, J. A. (2024). Quantum computing for resource allocation in cloud-edge environments: A VQE and QAOA approach. IEEE Access, 12:30030–30044.

Glover, F., Kochenberger, G., e Du, Y. (2019). Quantum bridge analytics I: A tutorial on formulating and using QUBO models. 4OR: A Quarterly Journal of Operations Research, 17(4):335–371.

Gordon, L. A. e Loeb, M. P. (2002). The economics of information security investment. ACM Transactions on Information and System Security, 5(4):438–457.

Guney, E., Ehrenthal, J., e Hanne, T. (2025). Quantum approaches to the 0/1 multi-knapsack problem: QUBO formulation, penalty parameter characterization and analysis. In Proceedings of the 17th International Conference on Agents and Artificial Intelligence, volume 1 of QAIO, pages 815–823. INSTICC, SciTePress.

Kellerer, H., Pferschy, U., e Pisinger, D. (2004). Knapsack Problems. Springer, Berlin.

Lucas, A. (2014). Ising formulations of many NP problems. Frontiers in Physics, 2:5.

Martello, S. e Toth, P. (1990). Knapsack Problems: Algorithms and Computer Implementations. Wiley, Chichester.

MITRE Corporation (2024). MITRE ATT&CK: Adversarial Tactics, Techniques and Common Knowledge. [link].

Panda, S., Panaousis, E., Loukas, G., e Laoudias, C. (2020). Optimizing investments in cyber hygiene for protecting healthcare users. Preprint.

Sawik, T. (2022). A linear model for optimal cybersecurity investment in industry 4.0 supply chains. International Journal of Production Research, 60(4):1368–1385.

Sawik, T. e Sawik, B. (2022). A rough cut cybersecurity investment using portfolio of security controls with maximum cybersecurity value. International Journal of Production Research, 60(21):6556–6572.

Tsiodra, M., Panda, S., Chronopoulos, M., e Panaousis, E. (2023). Cyber risk assessment and optimization: A small business case study. IEEE Access, 11:44467–44481.
Publicado
01/09/2026
NASCIMENTO, Alexandre Ramos do; XEXÉO, José Antonio Moreira; PINTO, Raquel Coelho Gomes; SANTOS, Anderson Fernandes Pereira dos. Otimização de Investimentos em Cibersegurança Sob Restrições Orçamentárias. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 1436-1442. DOI: https://doi.org/10.5753/sbseg.2026.29271.