Survivability Model for Security and Dependability Analysis of a Vulnerable Critical System

被引:0
|
作者
Chang, Xiaolin [1 ]
Lv, Shaohua [1 ]
Rodriguez, Ricardo J. [2 ]
Trivedi, Kishor [3 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing, Peoples R China
[2] Acad Gen Mil, Ctr Univ Def, Zaragoza, Spain
[3] Duke Univ, Dept Elect & Comp Engn, Durham, NC 27706 USA
关键词
Reactive defense strategy; Quantitative analysis; Stochastic Reward Nets; Survivability; Security;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper aims to analyze transient security and dependability of a vulnerable critical system, under vulnerability-related attack and two reactive defense strategies, from a severe vulnerability announcement until the vulnerability is fully removed from the system. By severe, we mean that the vulnerability-based malware could cause significant damage to the infected system in terms of security and dependability while infecting more and more new vulnerable computer systems. We propose a Markov chain-based survivability model for capturing the vulnerable critical system behaviors during the vulnerability elimination process. A high-level formalism based on Stochastic Reward Nets is applied to automatically generate and solve the survivability model. Survivability metrics are defined to quantify system attributes. The proposed model and metrics not only enable us to quantitatively assess the system survivability in terms of security risk and dependability, but also provide insights on the system investment decision. Numerical experiments are constructed to study the impact of key parameters on system security, dependability and profit.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] A Dependability Model for TMR System
    Jun-Jie Peng1
    International Journal of Automation and Computing, 2012, (03) : 315 - 324
  • [22] A Dependability Model for TMR System
    Peng, Jun-Jie
    Liu, Yan-Ping
    Chen, Yuan-Yuan
    INTERNATIONAL JOURNAL OF AUTOMATION AND COMPUTING, 2012, 9 (03) : 315 - 324
  • [23] Evaluation Model of System Survivability
    LIU Yuling
    WuhanUniversityJournalofNaturalSciences, 2006, (06) : 1844 - 1848
  • [24] Towards a stochastic model for integrated security and dependability evaluation
    Sallhammar, Karin
    Helvik, Bjarne E.
    Knapskog, Svein J.
    FIRST INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, PROCEEDINGS, 2006, : 156 - +
  • [25] Dependability assessment of safety-critical system software by static analysis methods
    Nguyen, T
    Ourghanlian, A
    2003 INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS, PROCEEDINGS, 2003, : 75 - 79
  • [26] A survivability model for cluster system
    Aung, KMM
    Park, K
    Park, JS
    DISTRIBUTED AND PARALLEL COMPUTING, 2005, 3719 : 73 - 82
  • [27] Model-based evaluation: From dependability to security
    Nicol, DM
    Sanders, WH
    Trivedi, KS
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2004, 1 (01) : 48 - 65
  • [28] An efficient survivability hierarchy analysis model for networked information system
    Zhang, Lejun
    Guo, Lin
    Yang, Wu
    Wang, Wei
    Yang, Yongtian
    CIS: 2007 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PROCEEDINGS, 2007, : 759 - 762
  • [29] A network survivability model for critical national infrastructures
    Houck, DJ
    Kim, E
    O'Reilly, G
    Picklesimer, DD
    Uzunalioglu, H
    BELL LABS TECHNICAL JOURNAL, 2004, 8 (04) : 153 - 172
  • [30] A model with applications for data survivability in Critical Infrastructures
    Albano, Michele
    Chessa, Stefano
    Di Pietro, Roberto
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2009, 4 (04): : 629 - 639