首页> 外文学位 >A formal approach to practical network security management.
【24h】

A formal approach to practical network security management.

机译:正式的网络安全管理方法。

获取原文
获取原文并翻译 | 示例

摘要

When a system administrator configures a network so it is secure, he understands very well the users, data, and most importantly the intent---what he is trying to do. However, he has a limited understanding of the mechanisms by which components interact and the details of each component. He could easily misconfigure the network so a hacker could steal confidential data. In addition to this complexity, about one hundred new security vulnerabilities are found each week, which makes it even more difficult to manage the security of a network installation---because of the large number of program vulnerabilities and challenging time constraints. Even professional administrators find this a difficult (impossible) task. How does one enable the system administrator to securely configure the network with a limited understanding of its components, program bugs and their interactions?; The solution is a security analysis framework that modularises information flow between the system administrator, security expert and the bug expert. The administrator specifies what he is trying to do, the security expert specifies component behaviour, the bug expert specifies known bugs. We developed a rule based framework---Multihost, Multistage, Vulnerability Analysis (MulVAL)---to perform end-to-end, automatic analysis of multi-host, multi-stage attacks on a large network where hosts run different operating systems. The MulVAL framework has been demonstrated to be modular, flexible, scalable and efficient. We used the framework to find serious configuration vulnerabilities in software from several major vendors for the Windows XP platform.
机译:当系统管理员配置网络以使其安全时,他会很好地理解用户,数据,最重要的是他打算做的事情。但是,他对组件交互的机制以及每个组件的细节了解有限。他很容易配置错误的网络,因此黑客可以窃取机密数据。除了这种复杂性之外,每周还发现约一百个新的安全漏洞,这是因为存在大量程序漏洞和具有挑战性的时间限制,使得管理网络安装的安全性变得更加困难。甚至专业管理员也认为这是一项困难(不可能)的任务。如何使系统管理员在对网络的组件,程序错误及其交互有一定了解的情况下安全地配置网络?该解决方案是一个安全分析框架,用于模块化系统管理员,安全专家和错误专家之间的信息流。管理员指定他要执行的操作,安全专家指定组件的行为,错误专家指定已知的错误。我们开发了基于规则的框架-多主机,多阶段,漏洞分析(MulVAL)-在主机运行不同操作系统的大型网络上执行端到端,多主机,多阶段攻击的自动分析。 MulVAL框架已被证明是模块化,灵活,可扩展和高效的。我们使用该框架在Windows XP平台的多家主要供应商的软件中发现了严重的配置漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号