The Days Before Zero Day: Investment Models for Secure Software Engineering

The Days Before Zero Day: Investment Models for Secure Software Engineering
复制标题

零日之前的日子:安全软件工程的投资模型

DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
A. Simpson
A. Simpson
中科院分区:
--
文献类型:
--
作者:
A. Simpson

文献摘要

被引文献

相似文献

虽然大多数安全实践和支出都集中在开发后产品和企业方法上,但有些人试图将安全重点从我们管理的网络转移到我们构建的系统。蓬勃发展的安全软件工程 (SSE) 社区一直在寻求识别和支持基于传统软件工程的活动,这些活动可以解决漏洞的引入问题,以此作为在安全问题出现之前阻止其出现的一种手段。人们普遍认为,此类方法不仅有望限制风险并减少安全事件,而且也是一种有效的安全投资,可以减少总体安全支出。虽然目前正在采取许多举措来将此类上证所做法编纂成法,但尚未对经济因素进行处理。我们提出了一个初始模型,将 SSE 投资作为减少防御者对漏洞的不确定性的手段,同时提高攻击者的成本。这种方法被实例化为传统安全模型的伴随过程,我们使用(部署后)安全投资的迭代最弱链接(IWL)模型来演示如何在系统的生命周期中优化防御者的安全投资。结果表明,安全投资回报率(安全软件流程回报率 (ROSSP))有所增加,同时部署后成本也有所降低。我们希望该模型能够为更全面地处理安全投资铺平道路,将安全前和安全后投资统一起来,从而对软件系统的安全性产生更全面的看法。
While the majority of security practice — and spending — is focused on post-development products and enterprise approaches, some have sought to change the focus of security from the networks we manage to the systems we build. The burgeoning Secure Software Engineering (SSE) community has sought to identify and espouse activities, built upon traditional software engineering, that address the introduction of vulnerabilities as a means of stemming the growing tide of security problems before they can be realised. It is widely believed that not only do such approaches hold promise to limit exposure and reduce security incidents, but they are also a valid security investment that decreases overall security expenditure. While many initiatives are now underway to codify such SSE practices, a treatment of the economic considerations has yet to be conducted. We propose an initial model that captures SSE investment as a means of reducing defender uncertainty regarding vulnerabilities, while raising the cost to the attacker. This approach is instantiated as a companion process to traditional security models, and we use the Iterated Weakest Link (IWL) model of (post-deployment) security investment to demonstrate how defender security investment can be optimised over the system’s lifecycle. The results indicate both an increased return on security investment — the Return on Secure Software Process (ROSSP) — as well as reduced post-deployment costs. It is our hope that this model paves the way for a more comprehensive treatment of security investment that unifies preand post-security investment, leading to a more comprehensive view of security in software systems.