• DocumentCode
    3098371
  • Title

    Security Risk Management in Computing Systems with Constraints on Service Disruption

  • Author

    Bommannavar, Praveen ; Bambos, Nicholas

  • Author_Institution
    Manage. Sci. & Eng., Stanford Univ., Stanford, CA, USA
  • fYear
    2011
  • fDate
    July 31 2011-Aug. 4 2011
  • Firstpage
    1
  • Lastpage
    6
  • Abstract
    We present a model for keeping track of vulnerabilities in a networked computing system and study the tradeoff between risk mitigation and keeping disruption at an acceptable level. The tradeoff is such that one can either choose to perform maintenance of the computing system very frequently and experience low risk, or disrupt the system with less frequency, but bear more risk. Formally, we suppose there are n types of vulnerabilities, where each type is jointly characterized by (i) maliciousness, as measured by risk per time slot due to its presence and (ii) probability of occurrence. At each time step, at most one new vulnerability appears in the system, a property that follows if we take the discretized time step size to be small compared to the rate of arrivals for vulnerabilities. We consider a finite-horizon framework of duration N in which the number of times the network may be patched is M <; N. This limitation captures the fact that in many engineering systems we would like to limit the number of times processes are interrupted for maintenance. Indeed, service providers may wish to promise clients that service will be disrupted no more than M times so that a certain level of operational continuity can be guaranteed. We develop an optimal policy for mitigating the risk due to exposure from vulnerabilities while obeying the patching constraint.
  • Keywords
    probability; risk management; scheduling; security of data; software maintenance; computing system maintenance; finite-horizon framework; maliciousness; networked computing system vulnerability; occurrence probability; operational continuity; optimal scheduling policy; patching constraint; risk mitigation; security risk management; service disruption; Computational modeling; Dynamic programming; Electronic mail; Maintenance engineering; Mathematical model; Risk management; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Communications and Networks (ICCCN), 2011 Proceedings of 20th International Conference on
  • Conference_Location
    Maui, HI
  • ISSN
    1095-2055
  • Print_ISBN
    978-1-4577-0637-0
  • Type

    conf

  • DOI
    10.1109/ICCCN.2011.6005875
  • Filename
    6005875