A game theoretic approach to vulnerability patching

A game theoretic approach to vulnerability patching
复制标题

漏洞修补的博弈论方法

DOI:
--
复制
发表时间:
2015
期刊:
2015 International Conference on Information and Communication Technology Research (ICTRC)
影响因子:
--
通讯作者:
Leopold Ghemmogne Fossi
Leopold Ghemmogne Fossi
中科院分区:
--
文献类型:
--
作者:
G. Gianini;M. Cremonini;Andrea Rainini;Guido Lena Cota;Leopold Ghemmogne Fossi

文献摘要

被引文献

相似文献

修补漏洞是安全管理中的关键活动之一。然而,对于大多数商业系统来说,相关漏洞的数量非常高;因此,实际上只能修复其中的一部分:由于资源有限,根据某些最佳标准选择它们对安全管理员来说是一个严峻的挑战。然而,我们还必须考虑到,即使是对漏洞进行攻击也需要付出不可忽视的努力:此外,潜在攻击者总是会受到有限资源的限制。对于黑客来说,根据一些最优标准选择攻击哪些漏洞也是一项艰巨的挑战。在这里,我们认为,如果两种类型的玩家都是理性的,希望最大化他们的ROI,并意识到问题的两面性,那么他们各自的策略可以在博弈论(GT)框架内更自然地讨论。我们开发了这样一个事实,即上述攻击/防御场景可以映射到GT模型的一个变体上,称为搜索游戏:我们称之为这个变体增强的漏洞修补游戏。在玩家理性的假设下,GT根据可能选择的概率分布来预测他们的行为:这一结果有助于支持资源受限的补丁管理的半自动选择。在这项工作中,我们建模和求解这类游戏的几个原型实例,并概述了走向更现实和准确的GT模型的道路。
Patching vulnerabilities is one of the key activities in security management. For most commercial systems however the number of relevant vulnerabilities is very high; as a consequence only a subset of them can be actually fixed: due to bounded resources, choosing them according to some optimal criterium is a critical challenge for the security manager. One has also to take into account, though, that even delivering attacks on vulnerabilities requires a non-negligible effort: also a potential attacker will always be constrained by bounded resources. Choosing which vulnerabilities to attack according to some optimality criterium is also a difficult challenge for a hacker. Here we argue that if both types of players are rational, wishing to maximize their ROI and aware of the two sides of the problem, their respective strategies can be discussed more naturally within a Game Theory (GT) framework. We develop the fact that the above described attack/defense scenario can be mapped onto a variant of GT models known as Search Games: we call this variant Enhanced Vulnerability Patching game. Under the hypothesis of rationality of the players, GT provides a prediction for their behavior in terms of a probability distribution over the possible choices: this result can help in supporting a semi-automatic choice of patch management with constrained resources. In this work we model and solve few prototypical instances of this class of games and outline the path towards more realistic and accurate GT models.