首页> 外文会议>2011 20th International Conference on Computer Communications and Networks >Security Risk Management in Computing Systems with Constraints on Service Disruption
【24h】

Security Risk Management in Computing Systems with Constraints on Service Disruption

机译:具有服务中断约束的计算系统中的安全风险管理

获取原文
获取外文期刊封面目录资料

摘要

We present a model for keeping track of vulnerabilities in a networked computing system and study the tradeoff between risk mitigation and keeping disruption at an acceptable level. The tradeoff is such that one can either choose to perform maintenance of the computing system very frequently and experience low risk, or disrupt the system with less frequency, but bear more risk. Formally, we suppose there are n types of vulnerabilities, where each type is jointly characterized by (i) maliciousness, as measured by risk per time slot due to its presence and (ii) probability of occurrence. At each time step, at most one new vulnerability appears in the system, a property that follows if we take the discretized time step size to be small compared to the rate of arrivals for vulnerabilities. We consider a finite-horizon framework of duration N in which the number of times the network may be patched is M < N. This limitation captures the fact that in many engineering systems we would like to limit the number of times processes are interrupted for maintenance. Indeed, service providers may wish to promise clients that service will be disrupted no more than M times so that a certain level of operational continuity can be guaranteed. We develop an optimal policy for mitigating the risk due to exposure from vulnerabilities while obeying the patching constraint.
机译:我们提出了一种模型,用于跟踪网络计算系统中的漏洞,并研究缓解风险和将中断保持在可接受水平之间的折衷方案。这种折衷使得人们可以选择非常频繁地执行计算系统的维护并降低风险,或者以较低的频率破坏系统,但承担更多的风险。形式上,我们假定存在n种类型的漏洞,其中每种漏洞的共同特征是(i)恶意,如通过每个时隙存在的风险和(ii)发生概率来衡量。在每个时间步长处,系统中最多会出现一个新漏洞,如果我们将离散时间步长的大小与漏洞的到达率相比较小,则会出现此属性。我们考虑持续时间为N的有限水平框架,其中网络可能被打补丁的次数为M

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号