Cyber vulnerability maintenance policies that address the incomplete nature of inspection

Cyber vulnerability maintenance policies that address the incomplete nature of inspection
复制标题

DOI:
10.1002/asmb.2487
复制
发表时间:
2019-10
影响因子:
1.4
通讯作者:
Enhao Liu;T. Allen;Sayak Roychowdhury
Enhao Liu;T. Allen;Sayak Roychowdhury
中科院分区:
数学4区
文献类型:
--
作者:
Enhao Liu;T. Allen;Sayak Roychowdhury

文献摘要

相似文献

在网络安全中,不完全检查主要是由于计算机在扫描过程中被关闭而导致的,这给计划维护行动带来了挑战。本文建议应用部分可观测的决策过程来得出成本效益最低的网络维护行动,从而使总成本最小化。我们考虑了几种类型的主机,它们具有不同严重程度的漏洞。在我们提出的模型中,维护成本结构包括维护行动的直接成本以及与不同安全状态相关联的潜在事故成本。为了评估从部分可观测的马尔可夫决策过程中获得的最优策略的好处,我们使用了来自一所主要大学的真实世界数据。与使用模拟的替代策略相比,最优控制策略可以显著降低每台主机的预期维护费用,并相对快速地缓解最重要的漏洞。
In cybersecurity, incomplete inspection, resulting mainly from computers being turned off during the scan, leads to a challenge for scheduling maintenance actions. This article proposes the application of partially observable decision processes to derive cost‐effective cyber maintenance actions that minimize total costs. We consider several types of hosts having vulnerabilities at various levels of severity. The maintenance cost structure in our proposed model consists of the direct costs of maintenance actions in addition to potential incident costs associated with different security states. To assess the benefits of optimal policies obtained from partially observable Markov decision processes, we use real‐world data from a major university. Compared with alternative policies using simulations, the optimal control policies can significantly reduce expected maintenance expenditures per host and relatively quickly mitigate the most important vulnerabilities.