首页> 外文期刊>Computer Journal, The >Compositional Approach to Quantify the Vulnerability of Computer Systems
【24h】

Compositional Approach to Quantify the Vulnerability of Computer Systems

机译:量化计算机系统漏洞的组合方法

获取原文
获取原文并翻译 | 示例
       

摘要

Although analyzing complex systems could be a complicated process, current approaches to quantify system security or vulnerability usually consider the whole system as a single component. In this paper, we propose a new compositional method to evaluate the vulnerability measure of complex systems. By the word composition we mean that the vulnerability measure of a complex system can be computed using pre-calculated vulnerability measures of its components. We define compatible systems to demonstrate which components could combine. Moreover, choice, sequential, parallel and synchronized parallel composition methods are defined and the measurement of the vulnerability in each case is presented. Our method uses a state machine to model the system. The model considers unauthorized states and attacker capabilities. Furthermore, both the probability of attack and delay time to reach the target state are used to quantify vulnerability. The proposed approach would be useful to analyze complex systems which may have complicated models. This approach reduces the state space and complexity of computation. On the other hand, if a component is replaced by another one, the vulnerability measures of other components do not change. Thus, these quantities are reused in new computation. Therefore, the calculation of the vulnerability measure for a new system is simplified.
机译:尽管分析复杂的系统可能是一个复杂的过程,但是目前用于量化系统安全性或漏洞的方法通常将整个系统视为单个组件。在本文中,我们提出了一种新的组合方法来评估复杂系统的脆弱性度量。组成一词是指可以使用预先计算的组件脆弱性度量来计算复杂系统的脆弱性度量。我们定义兼容的系统来演示可以组合的组件。此外,定义了选择,顺序,并行和同步并行组合方法,并给出了每种情况下漏洞的度量。我们的方法使用状态机对系统进行建模。该模型考虑了未经授权的状态和攻击者的能力。此外,攻击的可能性和到达目标状态的延迟时间都用于量化漏洞。所提出的方法对于分析可能具有复杂模型的复杂系统将很有用。这种方法减少了状态空间和计算复杂度。另一方面,如果一个组件被另一个组件替换,则其他组件的漏洞度量不会更改。因此,这些数量可在新的计算中重用。因此,简化了新系统的脆弱性度量的计算。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号