2008 the Third International Conference on Internet Monitoring and Protection 2008
DOI: 10.1109/icimp.2008.28
|View full text |Cite
|
Sign up to set email alerts
|

A Near Real-Time System for Security Assurance Assessment

Abstract: Building systems that are guaranteed to be secure or to remain secure over time is still an unachievable goal. The need for a tool that helps to determine security assurance level of a system is therefore vital in order to maintain and improve overall security. This paper introduces our system to assess the overall security assurance of a large, networked, IT-driven system in terms of a dedicated evaluation infrastructure based on multiagent technology. We use attack graph approach to compute an attackability … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

0
16
0

Year Published

2009
2009
2015
2015

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 13 publications
(16 citation statements)
references
References 15 publications
0
16
0
Order By: Relevance
“…This implies two countermeasures with the reduction effect of 60% or 0.6 and 80% (0.8) will cumulatively effect the same risk with (1-(1-0.6)*(1-0.8)) =1-(0.4)*(0.2) = 0.92. In case more than one risk is associated to an entity, a suitable aggregation function that we refer to as AGF should be selected to aggregate the corresponding reductions effect on those associated risks as shown in (2). This is relevant as risks to a system or an IT component will not have the same importance.…”
Section: Figure1 Security Assurance Aggregation Processmentioning
confidence: 99%
See 1 more Smart Citation
“…This implies two countermeasures with the reduction effect of 60% or 0.6 and 80% (0.8) will cumulatively effect the same risk with (1-(1-0.6)*(1-0.8)) =1-(0.4)*(0.2) = 0.92. In case more than one risk is associated to an entity, a suitable aggregation function that we refer to as AGF should be selected to aggregate the corresponding reductions effect on those associated risks as shown in (2). This is relevant as risks to a system or an IT component will not have the same importance.…”
Section: Figure1 Security Assurance Aggregation Processmentioning
confidence: 99%
“…Security assurance plays an important role in maintaining and improving the security level of system components and making them therefore more reliable. In that context, recent efforts [1] [2] within the field have been directed towards utilizing quantitative indicators in a more systematic and coordinated fashion to capture the security state of a particular Information Technology (IT) infrastructure. Until recently the focus was mainly on developing qualitative metrics that usually lead to security assurance levels that are either not accurate and/or not repeatable.…”
Section: Introductionmentioning
confidence: 99%
“…A comprehensive review of past attack graph research is presented in [8]. More recent approaches include [11], [18], and [19] Figure 6. Order of Vulnerability Instance Compromise in Six Scenarios.…”
Section: Related Workmentioning
confidence: 99%
“…The MulVAL system [21] used in [18] also does not explicitly model firewalls but assumes reachability is provided. Research in [19] uses our prior NetSPA system and thus scales well, but like our prior research, modern attacks and countermeasures are not modeled. Commercial attack graph products such as RedSeal [22] and Skybox [23] model firewalls and compute reachability from firewall rules but neither product's website mentions the ability to model personal firewalls, IPSs, or client side attacks.…”
Section: Related Workmentioning
confidence: 99%
“…Even if it was possible, assurance on security controls is very difficult once they have been deployed. Some researchers, such as Pham et al [22], have suggested using attack graphs and anomaly detection metrics. However, this approach lacks security effectiveness metrics.…”
Section: F Integration Of Metrics From Different Sources and Balancementioning
confidence: 99%