Risk management using behavior based Bayesian networks

被引:0
|
作者
Dantu, R [1 ]
Kolan, P [1 ]
机构
[1] Univ N Texas, Dept Comp Sci, Denton, TX 76203 USA
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Security administration is an uphill task to implement in an enterprise network providing secured corporate services. With the slew of patches being released by Microsoft, HP and other vendors, system administrators require a barrage of tools for analyzing the risk due to these vulnerabilities. In addition to this, criticalities in patching some end hosts (eg., in hospitals) raises serious security issues about the network to which the end hosts are connected. In this context, it would be imperative to know the risk level of all critical resources (e.g., Oracle Server in HR department) keeping in view the everyday emerging new vulnerabilities. We hypothesize that sequence of network actions by an attacker depends on the social behavior (e.g., skill level, tenacity, financial ability). We extended this and formulated a mechanism to estimate the risk level of critical resources that may be compromised based on attacker behavior. This estimation is accomplished using behavior based attack graphs. These graphs represent all the possible attack paths to all the critical resources. Based on these graphs, we calculate the risk level of a critical resource using Bayesian methodology and periodically update the subjective beliefs about the occurrence of an attack. Such a calculated risk level would be a measure of the vulnerability of the resource and it forms an effective basis for a system administrator to perform suitable changes to network configuration. Thus suitable vulnerability analysis and risk management strategies can be formulated to efficiently curtail the risk from different types of attackers (script kiddies, hackers, criminals and insiders).
引用
收藏
页码:115 / 126
页数:12
相关论文
共 50 条
  • [41] Risk-Based Fault Detection Using Bayesian Networks Based on Failure Mode and Effect Analysis
    Tarcsay, Balint Levente
    Barkanyi, Agnes
    Nemeth, Sandor
    Chovan, Tibor
    Lovas, Laszlo
    Egedy, Attila
    [J]. SENSORS, 2024, 24 (11)
  • [42] Health-Aware Economic MPC for Operational Management of Flow-Based Networks Using Bayesian Networks
    Pedrosa, Javier
    Puig, Vicenc
    Nejjari, Fatiha
    [J]. WATER, 2022, 14 (10)
  • [43] Economic Reliability-Aware MPC for Operational Management of Flow-Based Networks using Bayesian Networks
    Pedrosa, Javier
    Puig, Vicenc
    Nejjari, Fatiha
    [J]. 2022 30TH MEDITERRANEAN CONFERENCE ON CONTROL AND AUTOMATION (MED), 2022, : 884 - 889
  • [44] Automatic Learning of Attack Behavior Patterns Using Bayesian Networks
    Kavousi, Fatemeh
    Akbari, Behzad
    [J]. 2012 SIXTH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST), 2012, : 999 - 1004
  • [45] Modeling mobile apps user behavior using Bayesian networks
    Dharmasena I.
    Domaratzki M.
    Muthukumarana S.
    [J]. International Journal of Information Technology, 2021, 13 (4) : 1269 - 1277
  • [46] Prediction of human driving behavior using dynamic Bayesian networks
    Kumagai, T
    Akamatsu, M
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2006, E89D (02): : 857 - 860
  • [47] Risk Based Structural Integrity Management of Marine Platforms Using Bayesian Probabilistic Nets
    Montes-Iturrizaga, Roberto
    Heredia-Zavoni, Ernesto
    Vargas-Rodriguez, Francisco
    Faber, Michael Havbro
    Straub, Daniel
    de Dios de la O, Juan
    [J]. JOURNAL OF OFFSHORE MECHANICS AND ARCTIC ENGINEERING-TRANSACTIONS OF THE ASME, 2009, 131 (01): : 1 - 10
  • [48] Erratum to: Bayesian Networks-based Shield TBM Risk Management System: Methodology Development and Application
    Heeyoung Chung
    In-Mo Lee
    Jee-Hee Jung
    Jeongjun Park
    [J]. KSCE Journal of Civil Engineering, 2019, 23 : 3735 - 3735
  • [49] Fatigue analysis framework for fleet management using Bayesian networks
    Rosqvist, Tony
    Koski, Keijo
    Siljander, Aslak
    [J]. 2006 PROCEEDINGS - ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, VOLS 1 AND 2, 2006, : 133 - +
  • [50] Remote Coastal Weed Infestation Management Using Bayesian Networks
    Kininmonth, Stuart
    Spencer, Kerry
    Hill, Amie
    Sjerp, Eric
    Bangay, Jethro
    [J]. DIVERSITY-BASEL, 2024, 16 (07):