The Experts below are selected from a list of 14826 Experts worldwide ranked by ideXlab platform
Tadashi Dohi - One of the best experts on this subject based on the ideXlab platform.
-
a pull type security Patch Management of an intrusion tolerant system under a periodic vulnerability checking strategy
Computer Software and Applications Conference, 2018Co-Authors: Junjun Zheng, Hiroyuki Okamura, Tadashi DohiAbstract:In this paper, we consider a stochastic model to evaluate the system availability of an intrusion tolerant system (ITS), where the system undergoes the Patch Management with a periodic vulnerability checking strategy, i.e., a pull-type Patch Management. Based on the model, this paper discusses the appropriate timing for Patch applying. In particular, the paper models the attack behavior of adversary and the system behaviors under reactive defense strategies by a composite stochastic reward net (SRN). Furthermore, we formulate the interval availability by applying the phase-type (PH) approximation to solve the Markov regenerative process (MRGP) models derived from the SRNs. Numerical experiments are conducted to study the sensitivity of the system availability with respect to the number of checking.
-
Availability Analysis of an Intrusion Tolerant Distributed Server System With Preventive Maintenance
IEEE Transactions on Reliability, 2010Co-Authors: Toshikazu Uemura, Tadashi Dohi, Naoto KaioAbstract:We consider availability models of an intrusion tolerant system, and investigate quantitative effects of preventive maintenance based on security Patch releases. The stochastic behavior of the system is analyzed through an embedded Markov chain approach. More specifically, two semi-Markov models are formulated in continuous-time, and discrete-time scales. We derive the optimal preventive Patch Management times maximizing the steady-state system availability in respective models, and evaluate both the system availability, and the mean time to security failure. Numerical examples are presented for illustrating the optimal preventive maintenance policies, and performing sensitivity analysis of model parameters.
Naoto Kaio - One of the best experts on this subject based on the ideXlab platform.
-
Availability Analysis of an Intrusion Tolerant Distributed Server System With Preventive Maintenance
IEEE Transactions on Reliability, 2010Co-Authors: Toshikazu Uemura, Tadashi Dohi, Naoto KaioAbstract:We consider availability models of an intrusion tolerant system, and investigate quantitative effects of preventive maintenance based on security Patch releases. The stochastic behavior of the system is analyzed through an embedded Markov chain approach. More specifically, two semi-Markov models are formulated in continuous-time, and discrete-time scales. We derive the optimal preventive Patch Management times maximizing the steady-state system availability in respective models, and evaluate both the system availability, and the mean time to security failure. Numerical examples are presented for illustrating the optimal preventive maintenance policies, and performing sensitivity analysis of model parameters.
Jing Zhang - One of the best experts on this subject based on the ideXlab platform.
-
vulnerability severity prediction and risk metric modeling for software
Applied Intelligence, 2017Co-Authors: Jing ZhangAbstract:As more users suffer serious security threats from software vulnerabilities, software security becomes increasingly important. Vulnerability prediction and risk evaluation are two of the most concerning issues in software security Management. In this paper, we propose a prediction model for software vulnerability in which the probability and severity of vulnerability occurrence are determined by the logistic function and binomial distribution, respectively. Using the parameters obtained by prediction, we developed a new risk metric model. We provided some metrics, including mean time to vulnerability, local risk rate, mean risk rate, and overall risk value, from the viewpoint of time and probability. Experiments were conducted on real software vulnerability datasets. The results show that the prediction is effective and the evaluation is easy to operate. Our work has several features: (1) users can predict the vulnerability state in the future, in particular, vulnerability severity; (2) unlike traditional evaluation methods with expert scoring, our evaluation model is based on prediction and uses historical vulnerability data; and (3) the risk metric value can be used in risk assessment, security rating, and Patch Management.
Toshikazu Uemura - One of the best experts on this subject based on the ideXlab platform.
-
Availability Analysis of an Intrusion Tolerant Distributed Server System With Preventive Maintenance
IEEE Transactions on Reliability, 2010Co-Authors: Toshikazu Uemura, Tadashi Dohi, Naoto KaioAbstract:We consider availability models of an intrusion tolerant system, and investigate quantitative effects of preventive maintenance based on security Patch releases. The stochastic behavior of the system is analyzed through an embedded Markov chain approach. More specifically, two semi-Markov models are formulated in continuous-time, and discrete-time scales. We derive the optimal preventive Patch Management times maximizing the steady-state system availability in respective models, and evaluate both the system availability, and the mean time to security failure. Numerical examples are presented for illustrating the optimal preventive maintenance policies, and performing sensitivity analysis of model parameters.
Junjun Zheng - One of the best experts on this subject based on the ideXlab platform.
-
a pull type security Patch Management of an intrusion tolerant system under a periodic vulnerability checking strategy
Computer Software and Applications Conference, 2018Co-Authors: Junjun Zheng, Hiroyuki Okamura, Tadashi DohiAbstract:In this paper, we consider a stochastic model to evaluate the system availability of an intrusion tolerant system (ITS), where the system undergoes the Patch Management with a periodic vulnerability checking strategy, i.e., a pull-type Patch Management. Based on the model, this paper discusses the appropriate timing for Patch applying. In particular, the paper models the attack behavior of adversary and the system behaviors under reactive defense strategies by a composite stochastic reward net (SRN). Furthermore, we formulate the interval availability by applying the phase-type (PH) approximation to solve the Markov regenerative process (MRGP) models derived from the SRNs. Numerical experiments are conducted to study the sensitivity of the system availability with respect to the number of checking.