首页> 外文会议>IEEE Annual Computer Software and Applications Conference >A Pull-Type Security Patch Management of an Intrusion Tolerant System Under a Periodic Vulnerability Checking Strategy
【24h】

A Pull-Type Security Patch Management of an Intrusion Tolerant System Under a Periodic Vulnerability Checking Strategy

机译:周期性漏洞检查策略下入侵容忍系统的拉式安全补丁管理

获取原文

摘要

In this paper, we consider a stochastic model to evaluate the system availability of an intrusion tolerant system (ITS), where the system undergoes the patch management with a periodic vulnerability checking strategy, i.e., a pull-type patch management. Based on the model, this paper discusses the appropriate timing for patch applying. In particular, the paper models the attack behavior of adversary and the system behaviors under reactive defense strategies by a composite stochastic reward net (SRN). Furthermore, we formulate the interval availability by applying the phase-type (PH) approximation to solve the Markov regenerative process (MRGP) models derived from the SRNs. Numerical experiments are conducted to study the sensitivity of the system availability with respect to the number of checking.
机译:在本文中,我们考虑一种随机模型来评估入侵容忍系统(ITS)的系统可用性,在该系统中,系统会使用定期漏洞检查策略(即拉式补丁程序管理)进行补丁程序管理。基于该模型,本文讨论了补丁应用的适当时机。尤其是,本文通过复合随机奖励网络(SRN)对对手的攻击行为和反应性防御策略下的系统行为进行了建模。此外,我们通过应用相位类型(PH)近似来解决从SRN派生的马尔可夫再生过程(MRGP)模型来制定区间可用性。进行了数值实验,以研究系统可用性相对于检查次数的敏感性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号