首页> 外文期刊>ACM Computing Surveys >A Survey on Systems Security Metrics
【24h】

A Survey on Systems Security Metrics

机译:系统安全指标调查

获取原文
获取原文并翻译 | 示例
       

摘要

Security metrics have received significant attention. However, they have not been systematically explored based on the understanding of attack-defense interactions, which are affected by various factors, including the degree of system vulnerabilities, the power of system defense mechanisms, attack (or threat) severity, and situations a system at risk faces. This survey particularly focuses on how a system security state can evolve as an outcome of cyber attack-defense interactions. This survey concerns how to measure system-level security by proposing a security metrics framework based on the following four sub-metrics: (1) metrics of system vulnerabilities, (2) metrics of defense power, (3) metrics of attack or threat severity, and (4) metrics of situations. To investigate the relationships among these four sub-metrics, we propose a hierarchical ontology with four sub-ontologies corresponding to the four sub-metrics and discuss how they are related to each other. Using the four sub-metrics, we discuss the state-of-art existing security metrics and their advantages and disadvantages (or limitations) to obtain lessons and insight in order to achieve an ideal goal in developing security metrics. Finally, we discuss open research questions in the security metrics research domain and we suggest key factors to enhance security metrics from a system security perspective.
机译:安全指标已受到广泛关注。但是,尚未基于对攻击与防御交互的理解来系统地探索它们,该交互受各种因素影响,包括系统漏洞的程度,系统防御机制的功能,攻击(或威胁)严重性以及系统情况面临危险。这项调查特别关注系统安全状态如何随着网络攻击与防御交互而演变。该调查涉及如何通过基于以下四个子度量提出安全度量框架来度量系统级安全:(1)系统漏洞度量,(2)防御能力度量,(3)攻击或威胁严重性度量,以及(4)情况指标。为了研究这四个子度量之间的关系,我们提出了一个分层的本体,其中四个子本体分别与这四个子度量相对应,并讨论了它们如何相互关联。通过使用这四个子度量,我们讨论了现有的最新安全度量及其优缺点(或局限性),以获取经验教训和见识,从而实现开发安全度量的理想目标。最后,我们讨论安全性度量研究领域中的开放性研究问题,并从系统安全性角度提出增强安全性度量的关键因素。

著录项

  • 来源
    《ACM Computing Surveys》 |2017年第4期|62.1-62.35|共35页
  • 作者单位

    Univ Texas San Antonio, San Antonio, TX USA|One UTSA Circle, San Antonio, TX 78249 USA;

    Univ Texas San Antonio, San Antonio, TX USA|One UTSA Circle, San Antonio, TX 78249 USA;

    US Army, Res Lab, Adelphi, MD USA|US Army, Res Lab, Computat & Informat Sci Directorate, Adelphi, MD 20783 USA;

    Univ Texas San Antonio, San Antonio, TX USA|One UTSA Circle, San Antonio, TX 78249 USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Security metrics; security measurement; security foundation; quantitative security;

    机译:安全度量;安全度量;安全基础;定量安全;
  • 入库时间 2022-08-18 00:45:38

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号