Title :
A New Method for Modeling and Evaluation of the Probability of Attacker Success
Author :
Almasizadeh, Jaafar ; Azgomi, Mohammad Abdollahi
Author_Institution :
Dept. of Comput. Eng., Iran Univ. of Sci. & Technol., Tehran, Iran
Abstract :
Security quantification is a topic that has gained a lot of interest in the research community during the recent years. In this paper, a new method is proposed for modeling and quantifying attack effects on a computer system. In this work, intrusion process is considered as atomic sequential steps. Each atomic step changes the current system state. On the other hand, system tries to prevent and detect the attacker activity and therefore can transfer the current system state to a secure state. Intrusion process modeling is done by a semi-Markov chain (SMC). Distribution functions assigned to SMC transitions are uniform distributions. Uniform distributions represent the sojourn time of the attacker or the system in the transient states. Then the SMC is converted into a discrete-time Markov chain (DTMC). The DTMC is analyzed and then the probability of attacker success is computed based on mathematical theorems. The SMC has two absorbing for representing success and failure states of intrusion process.
Keywords :
Markov processes; discrete time systems; probability; security of data; statistical distributions; atomic sequential step; attacker success probability evaluation; computer system state; discrete-time Markov chain; intrusion process modeling; mathematical theorem; security quantification; semi-Markov chain; sojourn time; uniform distribution function; Computer networks; Computer security; Data security; Distribution functions; Equations; Petri nets; Quality of service; Sliding mode control; Stochastic processes; Stochastic systems; Markov Models; Security Evaluation; Security Modeling; semi-Markov chain;
Conference_Titel :
Security Technology, 2008. SECTECH '08. International Conference on
Conference_Location :
Hainan Island
Print_ISBN :
978-0-7695-3486-2
DOI :
10.1109/SecTech.2008.35