Survivability Model for Security and Dependability Analysis of a Vulnerable Critical System

被引:0
|
作者
Chang, Xiaolin [1 ]
Lv, Shaohua [1 ]
Rodriguez, Ricardo J. [2 ]
Trivedi, Kishor [3 ]
机构
[1] Beijing Jiaotong Univ, Beijing Key Lab Secur & Privacy Intelligent Trans, Beijing, Peoples R China
[2] Acad Gen Mil, Ctr Univ Def, Zaragoza, Spain
[3] Duke Univ, Dept Elect & Comp Engn, Durham, NC 27706 USA
关键词
Reactive defense strategy; Quantitative analysis; Stochastic Reward Nets; Survivability; Security;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
This paper aims to analyze transient security and dependability of a vulnerable critical system, under vulnerability-related attack and two reactive defense strategies, from a severe vulnerability announcement until the vulnerability is fully removed from the system. By severe, we mean that the vulnerability-based malware could cause significant damage to the infected system in terms of security and dependability while infecting more and more new vulnerable computer systems. We propose a Markov chain-based survivability model for capturing the vulnerable critical system behaviors during the vulnerability elimination process. A high-level formalism based on Stochastic Reward Nets is applied to automatically generate and solve the survivability model. Survivability metrics are defined to quantify system attributes. The proposed model and metrics not only enable us to quantitatively assess the system survivability in terms of security risk and dependability, but also provide insights on the system investment decision. Numerical experiments are constructed to study the impact of key parameters on system security, dependability and profit.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Survivability architecture of a mission critical system: The DPASA example
    Chong, J
    Pal, P
    Atigetchi, M
    Rubel, P
    Webber, F
    21ST ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2005, : 449 - 458
  • [42] A dependability analysis of an intrusion tolerance system
    Park, B
    Park, K
    Kim, S
    PDPTA '05: PROCEEDINGS OF THE 2005 INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED PROCESSING TECHNIQUES AND APPLICATIONS, VOLS 1-3, 2005, : 353 - 358
  • [43] Achieving critical system survivability through software architectures
    Knight, JC
    Strunk, EA
    ARCHITECTING DEPENDABLE SYSTEMS II, 2004, 3069 : 51 - 78
  • [44] Survivability as a Complementary Operational Security Model for IT Services (position paper)
    Hecker, Artur
    Riguidel, Michel
    SASOW 2008: SECOND IEEE INTERNATIONAL CONFERENCE ON SELF-ADAPTIVE AND SELF-ORGANIZING SYSTEMS WORKSHOPS, PROCEEDINGS, 2008, : 102 - 107
  • [45] Dependability analysis of safety critical and control systems of NPP
    Kamal Kaur, Raj
    Kumar Singh, Lalit
    Singh, Pooja
    Nuclear Engineering and Design, 2022, 399
  • [46] Multiformalism and Transformation Inheritance for Dependability Analysis of Critical Systems
    Marrone, Stefano
    Papa, Camilla
    Vittorini, Valeria
    INTEGRATED FORMAL METHODS, 2010, 6396 : 215 - +
  • [47] SURVIVABILITY OF SHIPS AT SEA: A PROPOSED MODEL TO ACCOUNT FOR HUMAN FACTORS IN A SAFETY-CRITICAL SYSTEM
    Rumawas, V.
    Asbjørnslett, B.E.
    Transactions of the Royal Institution of Naval Architects Part A: International Journal of Maritime Engineering, 2014, 156 (2 A):
  • [48] SURVIVABILITY OF SHIPS AT SEA: A PROPOSED MODEL TO ACCOUNT FOR HUMAN FACTORS IN A SAFETY-CRITICAL SYSTEM
    Rumawas, V.
    Asbjornslett, B. E.
    INTERNATIONAL JOURNAL OF MARITIME ENGINEERING, 2014, 156 : 137 - 147
  • [49] Dependability analysis of cyber security in All-Electric Ships
    Vicenzutti, A.
    Colavitto, A.
    Chiandone, M.
    Sulligoi, G.
    2018 AEIT INTERNATIONAL ANNUAL CONFERENCE, 2018,
  • [50] Dependability analysis of safety critical and control systems of NPP
    Kaur, Raj Kamal
    Singh, Lalit Kumar
    Singh, Pooja
    NUCLEAR ENGINEERING AND DESIGN, 2022, 399