首页> 外文会议>International Conference on Security Technology >A New Method for Modeling and Evaluation of the Probability of Attacker Success
【24h】

A New Method for Modeling and Evaluation of the Probability of Attacker Success

机译:一种建模与评估攻击者成功概率的新方法

获取原文

摘要

Security quantification is a topic that has gained a lot of interest in the research community during the recent years. In this paper, a new method is proposed for modeling and quantifying attack effects on a computer system. In this work, intrusion process is considered as atomic sequential steps. Each atomic step changes the current system state. On the other hand, system tries to prevent and detect the attacker activity and therefore can transfer the current system state to a secure state. Intrusion process modeling is done by a semi-Markov chain (SMC). Distribution functions assigned to SMC transitions are uniform distributions. Uniform distributions represent the sojourn time of the attacker or the system in the transient states. Then the SMC is converted into a discrete-time Markov chain (DTMC). The DTMC is analyzed and then the probability of attacker success is computed based on mathematical theorems. The SMC has two absorbing for representing success and failure states of intrusion process.
机译:安全量化是近年来在研究界中获得了很多兴趣的主题。在本文中,提出了一种用于对计算机系统进行建模和量化攻击效应的新方法。在这项工作中,入侵过程被认为是原子顺序步骤。每个原子步骤改变当前系统状态。另一方面,系统尝试防止并检测攻击者活动,因此可以将当前系统状态转移到安全状态。入侵过程建模由半马克可夫链(SMC)完成。分配给SMC转换的分发功能是均匀的分布。均匀分布表示攻击者或瞬态状态中的系统的静音时间。然后SMC被转换为离散时间马尔可夫链(DTMC)。分析DTMC,然后基于数学定理计算攻击者成功的概率。 SMC具有两种吸收,用于代表入侵过程的成功和失败状态。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号