Data Collection for Security Fault Forecasting - Pilot Experiment

作者: Tomas Olovsson , Bev Littlewood , Sarah Brocklehurst , Erland Jonsson

DOI:

关键词:

摘要: In most contexts, it is not feasible to guarantee that a system 100% secure. Measures and predictions of operational security computer systems are therefore obviously interest any owner which candidate for potential intruders. Such measures would allow assessment current future expected loss the due breaches in given attacking environment level protection. [Littlewood, Brocklehurst et al. 1991] probabilistic approach modelling security, analogous used reliability, suggested. It clear empirical data be useful deriving plausible modelling. can acquired experimentally, by allowing group selected people perform attacks on controlled way. The attack process then monitored relevant recorded. This document describes such an experiment. As far as we aware, this first attempt conduct experiment, our intention was more explore general feasibility than collect provides significant information pilot experiment did indeed give some valuable how full-scale experiments kind should performed results recommendations improvements experimental set-up discussed here. Release number 2 status Final

参考文章(5)
Tomas Olovsson, Erland Jonsson, Security forms for protection against vulnerabilities in computer systems IASTED International conference on Reliability, Quality control and Risk Assessment, Washington DC, USA.. pp. 138- 143 ,(1992)
Gene Spafford, Simson Garfinkel, Practical UNIX Security ,(1991)
Carl Martin Allwood, Carl-Gustav Björhag, Novices debugging when programming in Pascal International Journal of Human-computer Studies \/ International Journal of Man-machine Studies. ,vol. 33, pp. 707- 724 ,(1990) , 10.1016/S0020-7373(05)80070-7
F. T. Grampp, R. H. Morris, TheUNIXSystem: UNIXOperating System Security AT&T Bell Laboratories Technical Journal. ,vol. 63, pp. 1649- 1672 ,(1984) , 10.1002/J.1538-7305.1984.TB00058.X