SwePub
Sök i LIBRIS databas

  Extended search

id:"swepub:oai:research.chalmers.se:2ccddf9d-34d3-49c4-a355-3411a6847363"
 

Search: id:"swepub:oai:research.chalmers.se:2ccddf9d-34d3-49c4-a355-3411a6847363" > Security Assessment...

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Security Assessment Based on Attacker Behavior

Jonsson, Erland, 1946 (author)
Chalmers tekniska högskola,Chalmers University of Technology
Olovsson, Tomas, 1959 (author)
Chalmers tekniska högskola,Chalmers University of Technology
 (creator_code:org_t)
1996
1996
English.
In: Nordic Workshop on Secure Computer Systems, NORDSEC '96.
  • Conference paper (peer-reviewed)
Abstract Subject headings
Close  
  • This paper is based on a conceptual framework in which security can be split into two generic types of characteristics, behavioral and preventive. Here, preventive security denotes the system’s ability to protect itself from external attacks. One way to describe the preventive security of a system is in terms of its interaction with the alleged attacker, i.e., by describing the intrusion process. To our knowledge, very little is done to model this process in quantitative terms. Therefore, based on empirical data collected from intrusion experiments, we have worked out a hypothesis on typical attacker behavior. The hypothesis suggests that the attacking process can be split into three phases: the learning phase, the standard attack phase and the innovative attack phase. The probability for successful attacks during the learning and innovative phases is expected to be small, although for different reasons. During the standard attack phase it is expected to be considerably higher. The collected data indicates that the breaches during the standard attack phase are statistically equivalent and that the times between breaches are exponentially distributed. This would actually imply that traditional methods for reliability modeling could be applicable.

Subject headings

NATURVETENSKAP  -- Data- och informationsvetenskap -- Systemvetenskap, informationssystem och informatik (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Information Systems (hsv//eng)

Keyword

intrusion
modeling
Computer security
metric
attacks

Publication and Content Type

kon (subject category)
ref (subject category)

To the university's database

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Find more in SwePub

By the author/editor
Jonsson, Erland, ...
Olovsson, Tomas, ...
About the subject
NATURAL SCIENCES
NATURAL SCIENCES
and Computer and Inf ...
and Information Syst ...
Articles in the publication
By the university
Chalmers University of Technology

Search outside SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Close

Copy and save the link in order to return to this view