首页> 外文会议>International Conference on Cyber Situational Awareness, Data Analytics and Assessment >Cyber security: Influence of patching vulnerabilities on the decision-making of hackers and analysts
【24h】

Cyber security: Influence of patching vulnerabilities on the decision-making of hackers and analysts

机译:网络安全:修补漏洞对黑客和分析师决策的影响

获取原文

摘要

Patching of vulnerabilities on computer systems by analysts enables us to protect these systems from cyber-attacks. However, even after patching, the computer systems may still be vulnerable to cyber-attacks as the patching process may not be foolproof. Currently, little is known about how hacker's attack actions would be influenced by the varying effectiveness of the patching process. The primary objective of this study was to investigate the influence of the patching process on the attack-and-defend decisions of hackers and analysts. In this study, we used a 2-player zero-sum stochastic Markov security game in a lab-based experiment involving participants performing as hackers and analysts. In the experiment, participants were randomly assigned to two between-subjects patching conditions: effective (N = 50) and less-effective (N = 50). In effective patching, the probability of the network to be in a non-vulnerable state was 90% after patching by the analyst; whereas, in less-effective patching, the probability of the network to be in the non-vulnerable state was 50% after patching by the analyst. Results revealed that the proportion of attack and defend actions were similar between effective and less-effective conditions. Furthermore, although the proportion of defend actions were similar between vulnerable and non-vulnerable states, the proportion of attack actions were smaller in the non-vulnerable state compared to the vulnerable state. A majority of time, both players deviated significantly from their Nash equilibria in different conditions and states. We highlight the implications of our results for patching and attack actions in computer networks.
机译:分析人员修补计算机系统上的漏洞使我们能够保护这些系统免受网络攻击。但是,即使在修补之后,计算机系统仍可能容易受到网络攻击,因为修补过程可能并非万无一失。当前,对于补丁程序的有效性变化如何影响黑客的攻击行为知之甚少。这项研究的主要目的是调查补丁程序对黑客和分析师的攻防决策的影响。在这项研究中,我们在一个基于实验室的实验中使用了2人零和随机Markov安全游戏,参与者包括黑客和分析师。在实验中,参与者被随机分配到两个受试者之间的修补条件:有效(N = 50)和较差效(N = 50)。在有效的修补程序中,分析人员进行修补后,网络处于无漏洞状态的可能性为90%;相反,在修补效果较差的情况下,分析人员进行修补后,网络处于非脆弱状态的可能性为50%。结果显示,在有效状态和无效状态之间,进攻和防守行动的比例相似。此外,尽管脆弱状态和非脆弱状态之间防御动作的比例相似,但与脆弱状态相比,非脆弱状态下攻击动作的比例较小。在大多数情况下,两个玩家在不同条件和状态下均明显偏离纳什均衡。我们重点介绍了结果对计算机网络中的补丁和攻击行为的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号