De ning an Adaptive Software Security Metric from a Dynamic Software Failure Tolerance Measure
نویسنده
چکیده
This paper describes a software assessment method that is being implemented to quantitatively assess in formation system security and survivability Our ap proach which we call Adaptive Vulnerability Analysis exercises software in source code form by simulat ing incoming malicious and non malicious attacks that fall under various threat classes A quantitative met ric is computed by determining whether the simulated threats undermine the security of the system as de ned by the user according to the application program This approach stands in contrast to common security assur ance methods that rely on black box techniques for test ing completely installed systems AVA does not provide an absolute metric such as mean time to failure but instead provides a relative metric allowing a user to compare the security of di erent versions of the same system or to compare non related systems with similar
منابع مشابه
Dynamic Adaptive Search Based Software Engineering Needs Fast Approximate Metrics
Search Based Software Engineering (SBSE) uses fitness functions to guide an automated search for solutions to challenging software engineering problems. The fitness function is a form of software metric, so there is a natural and close interrelationship between software metics and SBSE. SBSE can be used as a way to experimentally validate metrics, revealing startling conflicts between metrics t...
متن کاملFormal approach on modeling and predicting of software system security: Stochastic petri net
To evaluate and predict component-based software security, a two-dimensional model of software security is proposed by Stochastic Petri Net in this paper. In this approach, the software security is modeled by graphical presentation ability of Petri nets, and the quantitative prediction is provided by the evaluation capability of Stochastic Petri Net and the computing power of Markov chain. Each...
متن کاملAdaptive Security Metrics for Computer Systems
The major concern for a computer system is its security and integrity. It is necessary to check the security level of your system and keep it updated. This can be best achieved by using a metric system. At present, there is no standard metric to measure the integrity and security of a computer system. Defining a standard metric that suits all the systems is difficult, considering the fact that ...
متن کاملSocial Computing and Usability Metrics: Toward User- Centered and Adaptive Interaction Agents
In this paper we propose to include two up-to-date separate concepts, namely social computing and usability metrics, in intelligent interaction agents to enhance a user-centered, adaptive human-computer interaction (HCI). Social computing refers to the application of sociological understanding to the design of interactive systems. We introduce accountability as an idea essential to social compu...
متن کاملAdaptation Space: Surviving Non-Maskable Failures
Some failures cannot be masked by redundancies, because an unanticipated situation occurred, because fault-tolerance measures were not adequate, or because there was a security breach (which is not amenable to replication). Applications that wish to continue to offer some service despite nonmaskable failure must adapt to the loss of resources. When numerous combinations of non-maskable failure ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 1996