• DocumentCode
    591790
  • Title

    Decision centric identification and rank ordering of security metrics

  • Author

    Khan, Mahrukh ; Omer, M. ; Copeland, John

  • Author_Institution
    Sch. of Electr. & Comput. Eng., Georgia Inst. of Technol., Atlanta, GA, USA
  • fYear
    2012
  • fDate
    22-25 Oct. 2012
  • Firstpage
    208
  • Lastpage
    211
  • Abstract
    A network has several attributes which play a role in determining the security of the network and its robustness to external threats. These attributes are related to security through a complex nonlinear function which is generally unknown to the network management personnel. Since the network security is an explicit function of these attributes, the managers do not realize when the value of a certain attribute has become critical to the point of threatening network security. In this paper we take a theoretically rigorous approach to quantifying the effect each of the individual attributes has on the network. By using ideas from probability and decision theory, we can order the significant factors determining network security. This is similar to dimensionality reduction which is commonly employed for model based identification methods. Based on our analysis we can come up with critical coefficients which must be maintained by the administrator if the network is to remain secure to external threats. We show how the mathematical framework leads to the prediction of network´s security health, and how real world data can be used to substantiate these claims. Paper concludes by validating our results on a list of compromised machine and determining if our identified metrics played the significant role in the infection.
  • Keywords
    computer network management; computer network security; decision theory; probability; complex nonlinear function; compromised machine; critical coefficients; decision centric identification; decision theory; dimensionality reduction; external threats; model based identification methods; network management personnel; network security health; probability; rank ordering; robustness; security metrics; Decision theory; Educational institutions; Measurement; Operating systems; Probability density function; Security; botnet; decision theory; pdf (probability density function); security metric; traffic characterization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks (LCN), 2012 IEEE 37th Conference on
  • Conference_Location
    Clearwater, FL
  • ISSN
    0742-1303
  • Print_ISBN
    978-1-4673-1565-4
  • Type

    conf

  • DOI
    10.1109/LCN.2012.6423610
  • Filename
    6423610