Proceedings of the 2004 Winter Simulation Conference R . G . Ingalls , M . D . Rossetti , J . S . Smith , and B . A . Peters , eds . FAST MODEL - BASED PENETRATION TESTING

نویسندگان

  • Sankalp Singh
  • James Lyons
  • David M. Nicol
چکیده

Traditional approaches to security evaluation have been based on penetration testing of real systems, or analysis of formal models of such systems. The former suffer from the problem that the security metrics are based on only a few of the possible paths through the system. The latter suffer from the inability to analyze detailed system descriptions due to the rapid explosion of state space sizes, which render the models intractable for tools such as model checkers. We propose an approach to obtain statistically valid estimates of security metrics by performing repeated penetration testing of detailed system models. We make use of importance sampling techniques to help reduce the variance of our estimates, and achieve relative error bounds quickly. We validate our approach by estimating security metrics of a large model with more than 21700 possible states.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

اثرات سایه اندازی روی سرعت و دوام پر شدن دانه و عملکرد ارقام باقلا

            آزمایشی دو ساله در مزرعه تحقیقاتی دانشکده کشاورزی دانشگاه تبریز در سال های 1381 و 1382 اجرا شد تا تاﺃتیر سایه اندازی روی روند پر شدن دانه و عملکرد ارقام باقلا ارزیابی شود. بذرهای سه رقم باقلا شامل برکت، سرازیری و HBP-B در هشت و 15 اردیبهشت ماه  با دست کاشته شدند. هر دو آزمایش بصورت اسپلیت پلات با طرح پایه بلوکهای کامل تصادفی با سه تکرار بودند. سطوح سایه در کرت های اصلی و ارقام درکرت...

متن کامل

Proceedings of the 2004 Winter Simulation

In this research, we investigate how well Weibull, Gamma, and special bimodal distribution are suited as an alternative to the exponential distribution approach in the stochastic modeling of machine downtimes and times between failures. We also discuss the question whether sampling shop-floor data should not only include first order statistics, but also measures that allow to monitor and model ...

متن کامل

بـررسی پتـانسیل اثـرات تغییر اقلیـم بر خشکسـالی‌های‌ آینـده کشـور با استفـاده از خروجی مـدل‌های گـردش عمـومی جـو

A Study of the Potential Impact of Climate Change on the Future Droughts in Iran by Using the Global Circulation Models as Outputs Gholamreza Roshan Assistant Professor in climatology, Department of Geography, Golestan University, Gorgan, Iran Mohammad Saeed Najafi  MSc Student in Climatology, Faculty of Geography, Tehran University, Tehran, Iran. Extended Abstract 1- Introductio...

متن کامل

Proceedings of the 2004 Winter Simulation Conference

In most scheduling literature, constraints are seemingly generated in an ad-hoc manner using intuitive arguments. This could result in overlooking some constraints or including unnecessary constraints. Schruben (2000) has shown how the dynamics of some discrete event systems can be modeled as the solutions of optimization programs. In this paper, we use this idea to generate mathematical progra...

متن کامل

Test of BibTEX references

[1] J. Stefanowski and D. Weiss, “Carrot2 and language properties in web search results clustering,” in Proceedings of AWIC-2003, First International Atlantic Web Intelligence Conference, ser. Lecture Notes in Computer Science, E. M. Ruiz, J. Segovia, and P. S. Szczepaniak, Eds., vol. 2663. Madrid, Spain: Springer, 2003, pp. 240–249. [Online]. Available: http://www.cs.put.poznan.pl/dweiss/xml/ ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004