Classification of Attributes and Behavior in Risk Management Using Bayesian Networks

Classification of Attributes and Behavior in Risk Management Using Bayesian Networks
复制标题

使用贝叶斯网络对风险管理中的属性和行为进行分类

DOI:
10.1109/isi.2007.379536
复制
发表时间:
2007
期刊:
2007 IEEE Intelligence and Security Informatics
影响因子:
--
通讯作者:
K. Loper
K. Loper
中科院分区:
--
文献类型:
--
作者:
R. Dantu;Prakash Kolan;R. Akl;K. Loper

文献摘要

被引文献

相似文献

在提供安全公司服务的企业网络中实现安全管理是一项艰巨的任务。随着网络组件供应商发布了大量补丁,系统管理员需要大量工具来分析这些组件中的漏洞所带来的风险。此外,对某些终端主机进行严重的修补会导致终端主机所连接的网络出现严重的安全问题。在这方面,必须了解所有关键资源的风险水平,同时考虑到每天出现的新脆弱性。我们假设攻击者的网络行动顺序取决于他们的社会和攻击概况(行为资源,如技能水平、时间和态度)。为了估计攻击行为的类型,我们调查了个人的能力和攻击意图。根据个人的反应,我们确定了他们的行为资源,并将他们分为机会主义者、黑客或探索者行为。具有该配置文件的攻击者可以使用配置文件行为资源来确定风险。从而制定合适的漏洞分析和风险管理策略,有效降低来自不同类型攻击者的风险。
Security administration is an uphill task to implement in an enterprise network providing secured corporate services. With the slew of patches being released by network component vendors, system administrators require a barrage of tools for analyzing the risk due to vulnerabilities in those components. In addition, criticalities in patching some end hosts raises serious security issues about the network to which the end hosts are connected. In this context, it would be imperative to know the risk level of all critical resources keeping in view the everyday emerging new vulnerabilities. We hypothesize that sequence of network actions by attackers depends on their social and attack profile (behavioral resources such as skill level, time, and attitude). To estimate the types of attack behavior, we surveyed individuals for their ability and attack intent. Using the individuals' responses, we determined their behavioral resources and classified them as having opportunist, hacker, or explorer behavior. The profile behavioral resources can be used for determining risk by an attacker having that profile. Thus, suitable vulnerability analysis and risk management strategies can be formulated to efficiently curtail the risk from different types of attackers.