Optimizing time allocation for network defence

Optimizing time allocation for network defence
复制标题

优化网络防御时间分配

DOI:
10.1093/cybsec/tyv002
复制
发表时间:
2015
影响因子:
3.9
通讯作者:
Caulfield T
Caulfield T
中科院分区:
--
文献类型:
--
作者:
Caulfield T

文献摘要

参考文献

被引文献

相似文献

软件中存在未修补的、可利用的漏洞是 这是许多形式网络攻击的先决条件。因为几乎不可避免的 发现漏洞并创建针对所有类型的 软件,多层安全通常用于保护重要系统 从妥协。因此,试图访问受保护系统的攻击者必须 绕过所有这些层。资源和资金有限的捍卫者必须 选择何时执行修补、监视和清理等操作 受感染的系统,以最好地保护他们的网络。同样,攻击者 还必须决定何时尝试渗透系统以及使用哪种漏洞利用 在这样做的时候。我们提出了一种建模计算机网络的方法, 漏洞,可用于找到时间的最佳分配, 不同的系统防御任务。系统的漏洞、状态和 攻击者和防御者的行为被用来建立部分可观察的 随机博弈这些游戏抓住了当前状态的不确定性, 系统和对未来的不确定性。这些博弈的解是 一种策略,它指示对于给定的信念采取的最佳行动, 系统的当前状态。我们用几个例子来说明这种方法。 不同的网络配置和播放器类型。我们认为这是一种权衡 对于系统管理员来说,他们必须分配时间来执行 安全相关任务或执行其他所需的非安全任务。 所提出的结果突出表明,由于其他任务的要求, 执行,遵循最佳策略意味着只花时间在最重要的事情上。 基本的安全相关任务,而大部分时间都花在 非安全任务。
The presence of unpatched, exploitable vulnerabilities in software is a prerequisite for many forms of cyberattack. Because of the almost inevitable discovery of a vulnerability and creation of an exploit for all types of software, multiple layers of security are usually used to protect vital systems from compromise. Accordingly, attackers seeking to access protected systems must circumvent all of these layers. Resource- and budget-constrained defenders must choose when to execute actions such as patching, monitoring and cleaning infected systems in order to best protect their networks. Similarly, attackers must also decide when to attempt to penetrate a system and which exploit to use when doing so. We present an approach to modelling computer networks and vulnerabilities that can be used to find the optimal allocation of time to different system defence tasks. The vulnerabilities, state of the system and actions by the attacker and defender are used to build partially observable stochastic games. These games capture the uncertainty about the current state of the system and the uncertainty about the future. The solution to these games is a policy, which indicates the optimal actions to take for a given belief about the current state of the system. We demonstrate this approach using several different network configurations and types of player. We consider a trade-off for the system administrator, where they must allocate their time to performing either security-related tasks or performing other required non-security tasks. The results presented highlight that, with the requirement for other tasks to be performed, following the optimal policy means spending time on only the most essential security-related tasks, while the majority of time is spent on non-security tasks.
DOI: --
发表时间: 2002-10
期刊: --
影响因子: --
作者:
S. Butler;P. Fischbeck
通讯作者: S. Butler;P. Fischbeck
使用贝叶斯网络对风险管理中的属性和行为进行分类
DOI: 10.1109/isi.2007.379536
发表时间: 2007
期刊: 2007 IEEE Intelligence and Security Informatics
影响因子: --
作者:
R. Dantu;Prakash Kolan;R. Akl;K. Loper
通讯作者: K. Loper
使用攻击者分析进行网络风险管理
DOI: 10.1002/sec.58
发表时间: 2009
期刊: Secur. Commun. Networks
影响因子: --
作者:
R. Dantu;Prakash Kolan;J. Cangussu
通讯作者: J. Cangussu
不安全流模型
DOI: --
发表时间: 1998
期刊: New Security Paradigms Workshop
影响因子: --
作者:
I. S. Moskowitz;Myong H. Kang
通讯作者: Myong H. Kang
DOI: 10.1016/j.ejor.2011.05.050
发表时间: 2012
期刊: Eur. J. Oper. Res.
影响因子: --
作者:
C. Ioannidis;D. Pym;Julian M. Williams
通讯作者: Julian M. Williams