首页> 外文会议>Proceedings 2015 Resilience Week >Quantifying minimizing attack surfaces containing moving target defenses
【24h】

Quantifying minimizing attack surfaces containing moving target defenses

机译:量化和最小化包含移动目标防御的攻击面

获取原文
获取原文并翻译 | 示例

摘要

The cyber security exposure of resilient systems is frequently described as an attack surface. A larger surface area indicates increased exposure to threats and a higher risk of compromise. Ad-hoc addition of dynamic proactive defenses to distributed systems may inadvertently increase the attack surface. This can lead to cyber friendly fire, a condition in which adding superfluous or incorrectly configured cyber defenses unintentionally reduces security and harms mission effectiveness. Examples of cyber friendly fire include defenses which themselves expose vulnerabilities (e.g., through an unsecured admin tool), unknown interaction effects between existing and new defenses causing brittleness or unavailability, and new defenses which may provide security benefits, but cause a significant performance impact leading to mission failure through timeliness violations. This paper describes a prototype service capability for creating semantic models of attack surfaces and using those models to (1) automatically quantify and compare cost and security metrics across multiple surfaces, covering both system and defense aspects, and (2) automatically identify opportunities for minimizing attack surfaces, e.g., by removing interactions that are not required for successful mission execution.
机译:弹性系统的网络安全隐患经常被描述为攻击面。较大的表面积表示增加了受到威胁的风险和较高的危害风险。向分布式系统临时添加动态主动防御可能会无意中增加攻击面。这可能会导致网络友好火灾,在这种情况下,添加多余的或配置错误的网络防御会无意间降低安全性并损害任务效率。网络友好之火的示例包括本身会暴露漏洞的防御(例如,通过不安全的管理工具),现有防御和新防御之间的未知交互作用(导致脆弱或不可用)以及可能提供安全优势但会导致重大性能影响的新防御违反及时性导致任务失败。本文介绍了一种原型服务功能,用于创建攻击面的语义模型,并使用这些模型来(1)​​自动量化和比较跨多个表面的成本和安全性指标,涵盖系统和防御方面,以及(2)自动识别将攻击面最小化的机会攻击面,例如,通过删除成功执行任务不需要的交互作用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号