...
首页> 外文期刊>Journal of defense modeling and simulatio >Selection of countermeasures against network attacks based on dynamical calculation of security metrics
【24h】

Selection of countermeasures against network attacks based on dynamical calculation of security metrics

机译:基于安全指标动态计算的网络攻击对策选择

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

This paper considers the issue of countermeasure selection for ongoing computer network attacks. We outline several challenges that should be overcome for the efficient response: the uncertainty of an attacker behavior, the complexity of interconnections between the resources of the modern distributed systems, the huge set of security data, time limitations, and balancing between countermeasure costs and attack losses. Although there are many works that are focused on the particular challenges, we suppose that there is still a need for an integrated solution that takes into account all of these issues. We suggest a model-driven approach to the security assessment and countermeasure selection in the computer networks that takes into account characteristics of different objects of assessment. The approach is based on integration with security information and event management systems to consider the dynamics of attack development, taking into account security event processing. Open standards and databases are used to automate security data processing. The suggested technique for countermeasure selection is based on the countermeasure model that was defined on the basis of open standards, the family of interrelated security metrics, and the security analysis technique based on attack graphs and service dependencies. We describe the prototype of the developed system and validate it on several case studies.
机译:本文考虑了针对正在进行的计算机网络攻击的对策选择问题。我们概述了有效响应应克服的几个挑战:攻击者行为的不确定性,现代分布式系统的资源之间互连的复杂性,大量安全数据,时间限制以及对策成本和攻击之间的平衡损失。尽管有许多针对特定挑战的工作,但我们认为仍然需要一种综合解决方案,其中要考虑所有这些问题。我们建议采用模型驱动的方法来考虑计算机网络中不同评估对象的特征,从而对计算机网络中的安全评估和对策进行选择。该方法基于与安全信息和事件管理系统的集成,以考虑攻击发展的动态,并考虑到安全事件处理。开放标准和数据库用于自动化安全数据处理。建议的对策选择技术基于在开放标准,相互关联的安全度量标准系列以及基于攻击图和服务依赖关系的安全分析技术的基础上定义的对策模型。我们描述了已开发系统的原型,并在一些案例研究中对其进行了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号