首页> 外文期刊>IEEE transactions on dependable and secure computing >Network Attack Surface: Lifting the Concept of Attack Surface to the Network Level for Evaluating Networks’ Resilience Against Zero-Day Attacks
【24h】

Network Attack Surface: Lifting the Concept of Attack Surface to the Network Level for Evaluating Networks’ Resilience Against Zero-Day Attacks

机译:网络攻击表面:将攻击面的概念提升到网络水平,以评估网络对零攻击的恢复力

获取原文
获取原文并翻译 | 示例

摘要

The concept of attack surface has seen many applications in various domains, e.g., software security, cloud security, mobile device security, Moving Target Defense (MTD), etc. However, in contrast to the original attack surface metric, which is formally and quantitatively defined for a software, most of the applications at higher abstraction levels, such as the network level, are limited to an intuitive and qualitative notion, losing the modeling power of the original concept. In this paper, we lift the attack surface concept to the network level as a formal security metric for evaluating the resilience of networks against zero day attacks. Specifically, we first develop novel models for aggregating the attack surface of different network resources. We then design heuristic algorithms to estimate the network attack surface while reducing the effort spent on calculating attack surface for individual resources. Finally, the proposed methods are evaluated through experiments.
机译:攻击表面的概念已经看到各个域中的许多应用,例如,软件安全性,云安全,移动设备安全性,移动目标防御(MTD)等。然而,与原始攻击表面度量相比,它们是正式和定量的为软件定义,大多数应用程序处于更高的抽象级别,例如网络级别,仅限于直观和定性的概念,丢失了原始概念的建模力。在本文中,我们将攻击表面概念提升到网络级别作为一种正式的安全性指标,用于评估网络对零日攻击的恢复性。具体而言,我们首先开发用于聚合不同网络资源的攻击表面的新型模型。然后,我们设计启发式算法来估计网络攻击表面,同时减少为单个资源计算攻击面的努力。最后,通过实验评估所提出的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号