DocumentCode :
3098371
Title :
Security Risk Management in Computing Systems with Constraints on Service Disruption
Author :
Bommannavar, Praveen ; Bambos, Nicholas
Author_Institution :
Manage. Sci. & Eng., Stanford Univ., Stanford, CA, USA
fYear :
2011
fDate :
July 31 2011-Aug. 4 2011
Firstpage :
1
Lastpage :
6
Abstract :
We present a model for keeping track of vulnerabilities in a networked computing system and study the tradeoff between risk mitigation and keeping disruption at an acceptable level. The tradeoff is such that one can either choose to perform maintenance of the computing system very frequently and experience low risk, or disrupt the system with less frequency, but bear more risk. Formally, we suppose there are n types of vulnerabilities, where each type is jointly characterized by (i) maliciousness, as measured by risk per time slot due to its presence and (ii) probability of occurrence. At each time step, at most one new vulnerability appears in the system, a property that follows if we take the discretized time step size to be small compared to the rate of arrivals for vulnerabilities. We consider a finite-horizon framework of duration N in which the number of times the network may be patched is M <; N. This limitation captures the fact that in many engineering systems we would like to limit the number of times processes are interrupted for maintenance. Indeed, service providers may wish to promise clients that service will be disrupted no more than M times so that a certain level of operational continuity can be guaranteed. We develop an optimal policy for mitigating the risk due to exposure from vulnerabilities while obeying the patching constraint.
Keywords :
probability; risk management; scheduling; security of data; software maintenance; computing system maintenance; finite-horizon framework; maliciousness; networked computing system vulnerability; occurrence probability; operational continuity; optimal scheduling policy; patching constraint; risk mitigation; security risk management; service disruption; Computational modeling; Dynamic programming; Electronic mail; Maintenance engineering; Mathematical model; Risk management; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Communications and Networks (ICCCN), 2011 Proceedings of 20th International Conference on
Conference_Location :
Maui, HI
ISSN :
1095-2055
Print_ISBN :
978-1-4577-0637-0
Type :
conf
DOI :
10.1109/ICCCN.2011.6005875
Filename :
6005875
Link To Document :
بازگشت