首页> 外文学位 >Attack Countermeasure Trees: A Non-state-space Approach Towards Analyzing Security and Finding Optimal Countermeasure Sets.
【24h】

Attack Countermeasure Trees: A Non-state-space Approach Towards Analyzing Security and Finding Optimal Countermeasure Sets.

机译:攻击对策树:一种用于分析安全性和找到最佳对策集的非状态空间方法。

获取原文
获取原文并翻译 | 示例

摘要

Attack tree (AT) is one of the widely used combinatorial models in security analysis. The basic formalism of AT does not take into account defense mechanisms. Defense trees (DTs) have been developed to investigate the effect of defense mechanisms using measures such as attack cost, security investment cost, return on attack (ROA) and return on investment (ROI). DT, however, places defense mechanisms only at the leaf nodes and the corresponding ROI/ROA analysis does not incorporate the probabilities of attack. In attack response tree (ART), attack and response are both captured but ART suffers from the problem of state-space explosion, since solution of ART is obtained by means of a partially observable Markov Decision Process model. In this thesis, we present a novel attack tree paradigm called attack countermeasure tree (ACT) which takes a purely noon-state-space approach to security analysis taking into account attacks as well as countermeasures (in the form of detection and mitigation techniques). In ACT, detection and mitigation are allowed not just at the leaf node but also at the intermediate nodes while at the same time the state-space explosion problem is avoided in its analysis. We propose algorithms to perform single and multiobjective optimization to find optimal countermeasure sets under different sets of budgetary constraints. We illustrate the features of ACT using several case studies.
机译:攻击树(AT)是安全分析中广泛使用的组合模型之一。 AT的基本形式主义没有考虑防御机制。已经开发了防御树(DT),以使用攻击成本,安全投资成本,攻击回报(ROA)和投资回报(ROI)等措施来研究防御机制的效果。但是,DT仅将防御机制放在叶节点上,并且相应的ROI / ROA分析没有考虑到攻击的可能性。在攻击响应树(ART)中,虽然捕获了攻击和响应,但是ART遭受了状态空间爆炸的问题,因为ART的解决方案是通过部分可观察的马尔可夫决策过程模型获得的。在本文中,我们提出了一种新颖的攻击树范例,称为攻击对策树(ACT),它采用纯正状态空间方法对安全性进行了分析,同时考虑了攻击和对策(以检测和缓解技术的形式)。在ACT中,不仅在叶节点而且在中间节点都允许检测和缓解,同时在分析中避免了状态空间爆炸问题。我们提出了执行单目标和多目标优化的算法,以找到在不同预算约束条件下的最佳对策集。我们使用几个案例研究来说明ACT的功能。

著录项

  • 作者

    Roy, Arpan.;

  • 作者单位

    Duke University.;

  • 授予单位 Duke University.;
  • 学科 Engineering Computer.;Computer Science.;Engineering Electronics and Electrical.
  • 学位 M.S.
  • 年度 2010
  • 页码 74 p.
  • 总页数 74
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号