Title :
Towards a stochastic model for integrated security and dependability evaluation
Author :
Sallhammar, Karin ; Helvik, Bjarne E. ; Knapskog, Svein J.
Author_Institution :
Centre for Quantifiable Quality of Service, Norwegian Univ. of Sci. & Technol., Trondheim, Norway
Abstract :
We present a new approach to integrated security and dependability evaluation, which is based on stochastic modelling techniques. Our proposal aims to provide operational measures of the trustworthiness of a system, regardless if the underlying failure cause is intentional or not. By viewing system states as elements in a stochastic game, we can compute the probabilities of expected attacker behavior, and thereby be able to model attacks as transitions between system states. The proposed game model is based on a reward-and cost concept. A section of the paper is devoted to the demonstration of how the expected attacker behavior is affected by the parameters of the game. Our model opens up for use traditional Markov analysis to make new types of probabilistic predictions for a system, such as its expected time to security failure.
Keywords :
Markov processes; probability; security of data; stochastic games; system recovery; Markov analysis; dependable computing; probabilistic prediction; reward and cost concept; security failure; stochastic game theory; stochastic model; Availability; Communication system security; Councils; Game theory; Information security; Predictive models; Proposals; Quality of service; Stochastic processes; Stochastic systems;
Conference_Titel :
Availability, Reliability and Security, 2006. ARES 2006. The First International Conference on
Print_ISBN :
0-7695-2567-9
DOI :
10.1109/ARES.2006.137