Risk management using behavior based Bayesian networks

被引:0
|
作者
Dantu, R [1 ]
Kolan, P [1 ]
机构
[1] Univ N Texas, Dept Comp Sci, Denton, TX 76203 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security administration is an uphill task to implement in an enterprise network providing secured corporate services. With the slew of patches being released by Microsoft, HP and other vendors, system administrators require a barrage of tools for analyzing the risk due to these vulnerabilities. In addition to this, criticalities in patching some end hosts (eg., in hospitals) raises serious security issues about the network to which the end hosts are connected. In this context, it would be imperative to know the risk level of all critical resources (e.g., Oracle Server in HR department) keeping in view the everyday emerging new vulnerabilities. We hypothesize that sequence of network actions by an attacker depends on the social behavior (e.g., skill level, tenacity, financial ability). We extended this and formulated a mechanism to estimate the risk level of critical resources that may be compromised based on attacker behavior. This estimation is accomplished using behavior based attack graphs. These graphs represent all the possible attack paths to all the critical resources. Based on these graphs, we calculate the risk level of a critical resource using Bayesian methodology and periodically update the subjective beliefs about the occurrence of an attack. Such a calculated risk level would be a measure of the vulnerability of the resource and it forms an effective basis for a system administrator to perform suitable changes to network configuration. Thus suitable vulnerability analysis and risk management strategies can be formulated to efficiently curtail the risk from different types of attackers (script kiddies, hackers, criminals and insiders).
引用
收藏
页码:115 / 126
页数:12
相关论文
共 50 条
  • [21] Using Bayesian Belief Networks to Investigate Farmer Behavior and Policy Interventions for Improved Nitrogen Management
    Felix Jäger
    Jessica Rudnick
    Mark Lubell
    Martin Kraus
    Birgit Müller
    [J]. Environmental Management, 2022, 69 : 1153 - 1166
  • [22] Operational Risk Management Based on Bayesian MCMC
    Zou, Qingzhong
    Li, Jinlin
    Ran, Lun
    [J]. IACSIT-SC 2009: INTERNATIONAL ASSOCIATION OF COMPUTER SCIENCE AND INFORMATION TECHNOLOGY - SPRING CONFERENCE, 2009, : 236 - 239
  • [23] Use of Bayesian Belief Networks for risk management in energy distribution
    Deleuze, G
    Bertin, H
    Dutfoy, A
    Pierlot, S
    Pourret, O
    [J]. PROBABILISTIC SAFETY ASSESSMENT AND MANAGEMENT, VOL 1- 6, 2004, : 814 - 818
  • [24] An Analytical Method for Multimorbidity Management Using Bayesian Networks
    Deparis, Stephane
    Pascale, Alessandra
    Tommasi, Pierpaolo
    Kotoulas, Spyros
    [J]. BUILDING CONTINENTS OF KNOWLEDGE IN OCEANS OF DATA: THE FUTURE OF CO-CREATED EHEALTH, 2018, 247 : 820 - 824
  • [25] Bayesian Networks-based Shield TBM Risk Management System: Methodology Development and Application
    Heeyoung Chung
    In-Mo Lee
    Jee-Hee Jung
    Jeongjun Park
    [J]. KSCE Journal of Civil Engineering, 2019, 23 : 452 - 465
  • [26] Decision Support for Maintenance Management Using Bayesian Networks
    Liu Yan
    Li Shi-qi
    [J]. 2007 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-15, 2007, : 5713 - 5716
  • [27] Data-driven Risk Management for Requirements Engineering: An Automated Approach based on Bayesian Networks
    Wiesweg, Florian
    Vogelsang, Andreas
    Mendez, Daniel
    [J]. 2020 28TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE (RE'20), 2020, : 125 - 135
  • [28] Bayesian Networks-based Shield TBM Risk Management System: Methodology Development and Application
    Chung, Heeyoung
    Lee, In-Mo
    Jung, Jee-Hee
    Park, Jeongjun
    [J]. KSCE JOURNAL OF CIVIL ENGINEERING, 2019, 23 (01) : 452 - 465
  • [29] Risk Assessment of Road Tunnels using Bayesian Networks
    Schubert, Matthias
    Hoj, Niels Peter
    Ragnoy, Arild
    Buvik, Harald
    [J]. TRANSPORT RESEARCH ARENA 2012, 2012, 48 : 2697 - 2706
  • [30] Risk assessment of decommissioning options using Bayesian networks
    Faber, MH
    Kroon, IB
    Kragh, E
    Bayly, D
    Decosemaeker, P
    [J]. JOURNAL OF OFFSHORE MECHANICS AND ARCTIC ENGINEERING-TRANSACTIONS OF THE ASME, 2002, 124 (04): : 231 - 238