• DocumentCode
    1994599
  • Title

    State space approach to security quantification

  • Author

    Griffin, Christopher ; Madan, Bharat ; Trivedi, Kishor

  • Author_Institution
    Pennsylvania State Univ., State College, PA, USA
  • Volume
    2
  • fYear
    2005
  • fDate
    26-28 July 2005
  • Firstpage
    83
  • Abstract
    In this paper, we describe three different state space models for analyzing the security of a software system. In the first part of this paper, we utilize a semi-Markov process (SMP) to model the transitions between the security states of an abstract software system. The SMP model can be solved to obtain the probability of reaching security failed states along with the meantime to security failure (MTTSF). In the second part of the paper, we use a discrete event dynamic system model of security dynamics. We show how to derive events and transitions from existing security taxonomies. We then apply theory of discrete event control to define safety properties of the computer system in terms of the basic concepts of controllability used in discrete event control for two special sublanguages Ks and Kv. These languages correspond to maximally robust controllable sub-languages. In the third approach, we show that by associating cost with the state transitions, the security quantification problem can be casted as Markov decision problem (MDP). This MOP can be solved to obtain an optimal controllable language Ks⊆Kv the gives the minimal cost safe security policy.
  • Keywords
    Markov processes; decision theory; discrete event systems; optimal control; security of data; state-space methods; MTTSF; Markov decision problem; abstract software system; discrete event control theory; discrete event dynamic system model; maximally robust controllable sub-language; meantime to security failure; minimal cost safe security policy; optimal controllable language; probability; security dynamics; security quantification; semi-Markov process model; software system security; state space model; state transition; Control systems; Controllability; Costs; Optimal control; Robust control; Safety; Security; Software systems; State-space methods; Taxonomy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference, 2005. COMPSAC 2005. 29th Annual International
  • ISSN
    0730-3157
  • Print_ISBN
    0-7695-2413-3
  • Type

    conf

  • DOI
    10.1109/COMPSAC.2005.145
  • Filename
    1508089