• DocumentCode
    2129557
  • Title

    An empirical model of the security intrusion process

  • Author

    Jonsson, Erland ; Olovsson, Tomas

  • Author_Institution
    Dept. of Comput. Eng., Chalmers Univ. of Technol., Goteborg, Sweden
  • fYear
    1996
  • fDate
    17-21 Jun 1996
  • Firstpage
    176
  • Lastpage
    186
  • Abstract
    The paper describes a security model developed from empirical data collected from a realistic intrusion experiment in which a number of undergraduate students were invited to attack a distributed computer system. Relevant data with respect to their intrusion activities were recorded continuously. We have worked out a hypothesis on typical attacker behavior based on experiences from this and other similar experiments. The hypothesis suggests that the attacking process can be split into three phases: the learning phase, the standard attack phase and the innovative attack phase. The probability for successful attacks during the learning phase is expected to be small and, if a breach occurs, it is rather a result of pure luck than deliberate action. During the standard attack phase, this probability is considerably higher whereas it decreases again in the innovative attack phase. The collected data indicates that the breaches during the standard attack phase are statistically equivalent. Furthermore, the times between breaches seem to be exponentially distributed, which means that traditional methods for reliability modeling of component failures may be applicable
  • Keywords
    access control; distributed processing; probability; safety; security of data; component failures; distributed computer system; empirical data; empirical model; intrusion activities; probability; realistic intrusion experiment; reliability modeling; security intrusion process; standard attack phase; typical attacker behavior; undergraduate students; Computer security; Data engineering; Data security; Distributed computing; Probability; Sections; Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Assurance, 1996. COMPASS '96, Systems Integrity. Software Safety. Process Security. Proceedings of the Eleventh Annual Conference on
  • Conference_Location
    Gaithersburg, MD
  • Print_ISBN
    0-7803-3390-X
  • Type

    conf

  • DOI
    10.1109/CMPASS.1996.507886
  • Filename
    507886