...
首页> 外文期刊>Annales des Telecommunications >Assessing the risk of complex ICT systems
【24h】

Assessing the risk of complex ICT systems

机译:评估复杂的ICT系统的风险

获取原文
获取原文并翻译 | 示例
           

摘要

AbstractICT systems are becoming increasingly complex and dynamic. They mostly include a large number of heterogeneous and interconnected assets (both physically and logically), which may be in turn exposed to multiple security flaws and vulnerabilities. Moreover, dynamicity is becoming paramount in modern ICT systems, since new assets and device configurations may be constantly added, updated, and removed from the system, leading to new security flaws that were not even existing at design time. From a risk assessment perspective, this adds new challenges to the defenders, as they are required to maintain risks within an acceptable range, while the system itself may be constantly evolving, sometimes in an unpredictable way. This paper introduces a new risk assessment framework that is aimed to address these specific challenges and that advances the state of the art along two distinct directions. First, we introduce the risk assessment graphs (RAGs), which provide a model and formalism that enable to characterize the system and its encountered risks. Nodes in the RAG represent each asset and its associated vulnerability, while edges represent the risk propagation between two adjacent nodes. Risk propagations in the graph are determined through two different metrics, namely the accessibility and potentiality, both formulated as a function of time and respectively capture the topology of the system and its risk exposure, as well as the way they evolve over time. Second, we introduce a quantitative risk assessment approach that leverages the RAGs in order to compute all possible attack paths in the system and to further infer their induced risks. Our approach achieves both flexibility and generality requirements and applies to a wide set of applications. In this paper, we demonstrate its usage in the context of a software-defined networking (SDN) testbed, and we conduct multiple experiments to evaluate the efficiency and scalability of our solution.
机译: Abstract ICT系统变得越来越复杂和动态。它们主要包括大量异构和相互关联的资产(物理上和逻辑上),这些资产又可能暴露于多个安全漏洞和漏洞。此外,由于新资产和设备配置可能会不断地从系统中添加,更新和删除,因此动态性在现代ICT系统中变得至关重要,从而导致设计时甚至不存在的新安全漏洞。从风险评估的角度来看,这给防御者带来了新的挑战,因为要求他们将风险保持在可接受的范围内,而系统本身可能会不断发展,有时会以无法预测的方式发展。本文介绍了一个新的风险评估框架,旨在应对这些特定挑战,并沿着两个不同的方向推进最新技术发展。首先,我们介绍风险评估图(RAG),这些图提供了模型和形式主义,可以表征系统及其遇到的风险。 RAG中的节点代表每个资产及其关联的漏洞,而边缘则代表两个相邻节点之间的风险传播。图中的风险传播是通过两个不同的指标来确定的,即可访问性和潜在性,它们都被表示为时间的函数,并分别捕获系统的拓扑结构及其风险暴露以及它们随时间演变的方式。其次,我们引入了一种定量风险评估方法,该方法利用RAG来计算系统中所有可能的攻击路径并进一步推断其诱发的风险。我们的方法达到了灵活性和通用性要求,并适用于广泛的应用程序。在本文中,我们演示了其在软件定义网络(SDN)测试平台中的用法,并进行了多次实验,以评估解决方案的效率和可扩展性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号