首页> 外文OA文献 >A pragmatic method for integrated modeling of security attacks and countermeasures
【2h】

A pragmatic method for integrated modeling of security attacks and countermeasures

机译:一种实用的安全攻击集成建模方法及对策

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In recent years, research efforts in cyber security have steadily increased as a result of growing concerns for cyber attacks and also increasing trend in cyber attack incidents. One of the important areas of research that is gaining importance is modeling of attacks and countermeasures to quantify survivability and other security measures of interest. In this context, on one extreme, attack trees model has received attention due to its simplicity and ease of analysis, and on the other extreme, stochastic models have been advocated. While attack trees model does not capture complex dependencies among events and also is not amenable for modeling dynamic nature of the attacks and countermeasures, the fitness of stochastic models is yet to be established as there is not sufficient evidence to show that attack and defense behaviors follow some known distributions. With this motivation, a new attack modeling approach based on Petri nets, called PENET, is developed in this thesis whose goal is to significantly enhance the modeling power of attack trees. PENET introduces relevant concepts such as dynamic nature of attack, repairability of a system, and the existence of recurring attacks. Moreover, it attempts to find a balance between ease of use and representation power by providing set of constructs, parameters, performance metrics, and time domain analysis of attack progress. Time domain analysis produces valuable output such as time to reach the main goal and the path taken by the attacker. This output helps to evaluate system survivability and defense strategies. This approach is implemented as a software tool, called PENET Tool, which lets users draw model diagrams of a given system through intuitive user interface, perform time domain simulations and carry out security evaluations, and enable interactive ways to improve the survivability of the system.
机译:近年来,由于对网络攻击的关注日益增加,并且网络攻击事件的趋势也在增加,因此网络安全方面的研究工作稳步增加。正在变得重要的重要研究领域之一是对攻击和对策进行建模,以量化生存能力和其他感兴趣的安全措施。在这种情况下,一方面,攻击树模型由于其简单性和易分析性而受到关注,另一方面,提倡随机模型。虽然攻击树模型不能捕获事件之间的复杂依赖性,也不适合对攻击的动态性质和对策进行建模,但由于尚无足够的证据表明攻击和防御行为遵循,随机模型的适用性尚待建立。一些已知的分布。基于这种动机,本文提出了一种新的基于Petri网的攻击建模方法,称为PENET,其目的是显着增强攻击树的建模能力。 PENET引入了相关的概念,例如攻击的动态性质,系统的可修复性以及重复发作的存在。此外,它试图通过提供一组结构,参数,性能指标以及攻击进度的时域分析来在易用性和表示能力之间找到平衡。时域分析会产生有价值的输出,例如达到主要目标所需的时间以及攻击者采取的路径。此输出有助于评估系统的生存能力和防御策略。这种方法是作为称为PENET工具的软件工具实现的,该工具使用户可以通过直观的用户界面绘制给定系统的模型图,执行时域仿真并执行安全性评估,并采用交互方式来提高系统的生存能力。

著录项

  • 作者

    Pudar, Srdjan;

  • 作者单位
  • 年度 2007
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号