首页> 外文会议>IEEE Conference on Local Computer Networks >Prioritize When Patching Everything is Impossible!
【24h】

Prioritize When Patching Everything is Impossible!

机译:修补一切不可能的时候优先考虑!

获取原文

摘要

Vulnerable critical networks are attractive targets for remote adversaries with different intentions. Towards enhancing resilience against extreme risks, such networks need to continuously assess their security posture and prioritize possible remediation actions based on security risk. The contribution of this work is to provide an integrated risk-based decision-support methodology for prioritizing risk remediation activities. Our methodology leverages the Time-To-Compromise security metric to quantitatively assess the compromise risk. Furthermore, it employs game-theory principles to model the strategic behaviour of the involved players (e.g., defender and attacker). The novelty of this approach lies in the way it integrates the risk attitude of the decision makers involved in the patch management operations across critical organizations into the prioritization process.
机译:易受攻击的关键网络是具有不同意图的远程对手的吸引力目标。为了加强对极端风险的恢复力,这种网络需要不断评估其安全姿势,并根据安全风险确定可能的修复行为。这项工作的贡献是提供一种综合风险的决策支持方法,以优先考虑风险修复活动。我们的方法利用时间妥协的安全度量来定量地评估妥协风险。此外,它采用了博弈论原则来模拟所涉及的球员(例如,后卫和攻击者)的战略行为。这种方法的新颖性在于它将涉及关键组织涉及的决策者的风险态度整合到优先级进入的问题。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号