Survivability Model for Security and Dependability Analysis of a Vulnerable Critical System

被引:0
|
作者
Chang, Xiaolin [1 ]
Lv, Shaohua [1 ]
Rodriguez, Ricardo J. [2 ]
Trivedi, Kishor [3 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing, Peoples R China
[2] Acad Gen Mil, Ctr Univ Def, Zaragoza, Spain
[3] Duke Univ, Dept Elect & Comp Engn, Durham, NC 27706 USA
关键词
Reactive defense strategy; Quantitative analysis; Stochastic Reward Nets; Survivability; Security;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper aims to analyze transient security and dependability of a vulnerable critical system, under vulnerability-related attack and two reactive defense strategies, from a severe vulnerability announcement until the vulnerability is fully removed from the system. By severe, we mean that the vulnerability-based malware could cause significant damage to the infected system in terms of security and dependability while infecting more and more new vulnerable computer systems. We propose a Markov chain-based survivability model for capturing the vulnerable critical system behaviors during the vulnerability elimination process. A high-level formalism based on Stochastic Reward Nets is applied to automatically generate and solve the survivability model. Survivability metrics are defined to quantify system attributes. The proposed model and metrics not only enable us to quantitatively assess the system survivability in terms of security risk and dependability, but also provide insights on the system investment decision. Numerical experiments are constructed to study the impact of key parameters on system security, dependability and profit.
引用
收藏
页数:6
相关论文
共 50 条
  • [31] 9.4.2 Incorporating Security and Survivability into the System of Systems Architecting
    Singh, Atmika
    Dagli, Cihan
    INCOSE International Symposium, 2007, 17 (01) : 1570 - 1578
  • [32] Predictive Analysis of Mission Critical Systems Dependability
    Danhel, Martin
    Kubatova, Hana
    Dobias, Radek
    16TH EUROMICRO CONFERENCE ON DIGITAL SYSTEM DESIGN (DSD 2013), 2013, : 561 - 566
  • [33] Survivability analysis of a cluster system with 4th generation security mechanism: Regeneration
    Network Security Lab., Computer Engineering Dept., Hankuk Aviation University, 412-791, Seoul, Korea, Republic of
    不详
    Int. J. Netw. Secur., 2006, 3 (271-278):
  • [34] A Novel Quantitative Analysis Model for Information System Survivability Based on Conflict Analysis
    Department of Computer Science and Technology, Harbin Engineering University, Harbin, 150001, China
    不详
    Tsinghua Sci. Tech., 2007, SUPPL. 1 (217-222):
  • [35] Analysis of Cybersecurity Mechanisms with respect to Dependability and Security Attributes
    Sangchoolie, Behrooz
    Folkesson, Peter
    Kleberger, Pierre
    Vinter, Jonny
    50TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W 2020), 2020, : 94 - 101
  • [36] Frailty modelling for risk analysis in network security and survivability
    Ma Z.S.
    International Journal of Information and Computer Security, 2011, 4 (03) : 276 - 294
  • [37] Security Analysis: From Model to System Analysis
    Drouot, Bastien
    Monthe, Valery
    Guerin, Sylvain
    Champeau, Joel
    RISKS AND SECURITY OF INTERNET AND SYSTEMS, CRISIS 2022, 2023, 13857 : 133 - 152
  • [38] A survivability quantitative analysis model for network system based on attack graph
    Zhang, Le-Jun
    Wang, Wei
    Guo, Lin
    Yang, Wu
    Yang, Yong-Tian
    PROCEEDINGS OF 2007 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2007, : 3211 - 3216
  • [39] A distributed monitoring system for enhancing security and dependability at architectural level
    Inverardi, Paola
    Mostarda, Leonardo
    ARCHITECTING DEPENDABLE SYSTEMS IV, 2007, 4615 : 210 - +
  • [40] Justifying the Dependability and Security of Business-Critical Blockchain-based Applications
    Piriou, Pierre-Yves
    Boudeville, Olivier
    Deleuze, Gilles
    Tucci-Piergiovanni, Sara
    Gurcan, Onder
    2021 THIRD INTERNATIONAL CONFERENCE ON BLOCKCHAIN COMPUTING AND APPLICATIONS (BCCA), 2021, : 97 - 104