首页> 外文会议>Computer security - ESORICS 2010 >A Service Dependency Model for Cost-Sensitive Intrusion Response
【24h】

A Service Dependency Model for Cost-Sensitive Intrusion Response

机译:成本敏感型入侵响应的服务依赖模型

获取原文
获取原文并翻译 | 示例

摘要

Recent advances in intrusion detection and prevention have brought promising solutions to enhance IT security. Despite these efforts, the battle with cyber attackers has reached a deadlock. While attackers always try to unveil new vulnerabilities, security experts are bounded to keep their softwares compliant with the latest updates. Intrusion response systems are thus relegated to a second rank because no one trusts them to modify system configuration during runtime. Current response cost evaluation techniques do not cover all impact aspects, favoring availability over confidentiality and integrity. They do not profit from the findings in intrusion prevention which led to powerful models including vulnerability graphs, exploit graphs, etc. This paper bridges the gap between these models and service dependency models that are used for response evaluation. It proposes a new service dependency representation that enables intrusion and response impact evaluation. The outcome is a service dependency model and a complete methodology to use this model in order to evaluate intrusion and response costs. The latter covers response collateral damages and positive response effects as they reduce intrusion costs.
机译:入侵检测和防御的最新进展带来了有希望的解决方案,以增强IT安全性。尽管做出了这些努力,与网络攻击者的战斗陷入了僵局。尽管攻击者总是试图揭露新漏洞,但安全专家必须确保其软件与最新更新兼容。由于没有人信任入侵响应系统在运行时修改系统配置,因此入侵响应系统被降为第二等级。当前的响应成本评估技术并未涵盖所有影响方面,因此倾向于可用性而不是机密性和完整性。他们不能从入侵防御的发现中受益,入侵防御的发现导致了功能强大的模型,包括漏洞图,漏洞利用图等。本文在这些模型与用于响应评估的服务依赖模型之间架起了桥梁。它提出了一种新的服务依赖关系表示形式,可以实现入侵和响应影响评估。结果是服务依赖关系模型和使用该模型的完整方法,以便评估入侵和响应成本。后者涵盖了响应附带损害和积极响应效果,因为它们降低了入侵成本。

著录项

  • 来源
    《Computer security - ESORICS 2010》|2010年|p.626-642|共17页
  • 会议地点 Athens(GR);Athens(GR)
  • 作者单位

    Telecom Bretagne, 2 rue de la Chataigneraie, 35512 Cesson Sevigne, Prance,France Telecom RD, 42 Rue des Coutures, 14066 Caen, France;

    Telecom Bretagne, 2 rue de la Chataigneraie, 35512 Cesson Sevigne, Prance;

    Telecom Bretagne, 2 rue de la Chataigneraie, 35512 Cesson Sevigne, Prance;

    Telecom SudParis, 9 rue Charles Fourier, 91011 Evry, France;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;
  • 关键词

  • 入库时间 2022-08-26 13:47:59

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号