首页> 外文会议>Annual IFIP WG 11.3 conference on data and applications security and privacy >Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options
【24h】

Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options

机译:使用异构强化选项保护网络免受不可修补和未知的漏洞的侵害

获取原文

摘要

The administrators of a mission critical network usually have to worry about non-traditional threats, e.g., how to live with known, but unpatchable vulnerabilities, and how to improve the network's resilience against potentially unknown vulnerabilities. To this end, network hardening is a well-knowfn preventive security solution that aims to improve network security by taking proactive actions, namely, hardening options. However, most existing network hardening approaches rely on a single hardening option, such as disabling unnecessary services, which becomes less effective when it comes to dealing with unknown and unpatchable vulnerabilities. There lacks a heterogeneous approach that can combine different hardening options in an optimal way to deal with both unknown and unpatchable vulnerabilities. In this paper, we propose such an approach by unifying multiple hardening options, such as firewall.rule modification, disabling services, service diversification, and access control, under the same model. We then apply security metrics designed for evaluating network resilience against unknown and unpatchable vulnerabilities, and consequently derive optimal hardening solutions that maximize security under given cost constraints.
机译:关键任务网络的管理员通常必须担心非传统威胁,例如,如何忍受已知但无法修补的漏洞,以及如何提高网络抵御潜在未知漏洞的能力。为此,网络强化是众所周知的预防性安全解决方案,旨在通过采取主动措施(即强化选项)来提高网络安全性。但是,大多数现有的网络强化方法都依赖于单个强化选项,例如禁用不必要的服务,当处理未知且不可修补的漏洞时,这种方法的有效性降低。缺少一种可以以最佳方式组合不同强化选项来处理未知和不可修补漏洞的异构方法。在本文中,我们通过统一多个强化选项,例如防火墙,规则修改,禁用服务,服务多样化和访问控制,在同一模型下提出了这种方法。然后,我们应用旨在评估针对未知和不可修补的漏洞的网络弹性的安全度量,并因此得出最佳强化解决方案,以在给定的成本约束下最大限度地提高安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号