首页> 外文会议>Security and privacy-silver linings in the cloud >Ex-SDF: An Extended Service Dependency Framework for Intrusion Impact Assessment
【24h】

Ex-SDF: An Extended Service Dependency Framework for Intrusion Impact Assessment

机译:前SDF:用于入侵影响评估的扩展服务依赖关系框架

获取原文
获取原文并翻译 | 示例

摘要

Information systems are increasingly dependent on highly distributed architectures that include multiple dependencies. Even basic attacks like script-kiddies have drastic effects on target systems as they easily spread through existing dependencies. Unless intrusion effects are accurately assessed, response systems will still be blinded when selecting optimal responses. In fact, using only response costs as a basis to select responses is still meaningless if not compared to intrusion costs. While conventional responses provoke mostly availability impacts, intrusions affect confidentiality, integrity and availability. This paper develops an approach to assess intrusion impacts on IT systems. It uses service dependencies as frames for propagating impacts. It goes beyond existing methods which mostly use dependability anal ysis techniques. It explores service privileges as being the main targets for attackers, and the tunable parameters for intrusion response. The approach presented in this paper is implemented as a simulation-based framework and demonstrated for the example of a vehicle reservation service.
机译:信息系统越来越依赖高度分散的体系结构,该体系结构包含多个依赖性。甚至像脚本之类的基本攻击也会对目标系统产生巨大影响,因为它们很容易通过现有依赖项传播。除非准确评估入侵效果,否则在选择最佳响应时响应系统仍然是盲目的。实际上,仅将响应成本作为选择响应的基础,即使与入侵成本相比也没有任何意义。尽管传统的响应方式主要引起可用性方面的影响,但入侵会影响机密性,完整性和可用性。本文提出了一种评估入侵对IT系统影响的方法。它使用服务依赖项作为传播影响的框架。它超越了大多数使用可靠性分析技术的现有方法。它探索服务特权作为攻击者的主要目标,以及入侵响应的可调参数。本文提出的方法是作为基于仿真的框架实现的,并以车辆预订服务为例进行了演示。

著录项

  • 来源
  • 会议地点 Brisbane(AU);Brisbane(AU);Brisbane(AU);Brisbane(AU)
  • 作者单位

    Telecom Bretagne,2 rue de la Chataigneraie, 35512 Cesson Sevigne, France, France Telecom RD, 42 rue des Coutures, 14066 Caen, France;

    Telecom Bretagne,2 rue de la Chataigneraie, 35512 Cesson Sevigne, France;

    Telecom Bretagne,2 rue de la Chataigneraie, 35512 Cesson Sevigne, France;

    Telecom SudParis, 9 rue Charles Fourier, 91011 Evry, France;

  • 会议组织
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类 安全保密;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号