【24h】

How Well Can I Secure My System?

机译:我如何保护我的系统?

获取原文

摘要

Securing a system, being it a computer network, a physical infrastructure or an organization, is a very challenging task. In practice, it is always constrained by available resources, e.g., budget, time, or man-power. An attack-defense tree is a security model allowing to reason about different strategies that an attacker may use to attack a system and potential countermeasures that a defender could apply to defend against such attacks. This work integrates the modeling power of attack-defense trees with the strengths of integer linear programming techniques. We develop a framework that, given the overall budget allocated for the system's protection, suggests which countermeasures should be implemented to secure the system in the best way possible. We lay down formal foundations for our framework and implement a proof of concept tool automating the solving of relevant optimization problems.
机译:保护系统(无论是计算机网络,物理基础结构还是组织)是一项非常艰巨的任务。实际上,它总是受到可用资源的限制,例如预算,时间或人力。攻击防御树是一种安全模型,允许推理出​​攻击者可以用来攻击系统的不同策略以及防御者可以用来防御此类攻击的潜在对策。这项工作将攻击防御树的建模能力与整数线性规划技术的优势整合在一起。我们开发了一个框架,考虑到为保护系统分配的总预算,该框架建议应采取哪些对策以尽可能最佳的方式保护系统。我们为我们的框架奠定了正式的基础,并实施了概念证明工具来自动解决相关的优化问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号