Risk-aware framework for activating and deactivating policy-based response - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2010

Risk-aware framework for activating and deactivating policy-based response

Résumé

With the growth of modern systems and infrastructures, automated and intelligent response systems become the holy grail of the security community. An interesting approach proposes to use dynamic access control policies to specify response policies for such systems. These policies should be enforced when an ongoing attack, that threatens the monitored system, is detected. However, existing work do not present a clear methodology to specify the Response policies. In particular, the deactivation issue is not yet tackled. In this paper, we first present how to specify response policies. Second, a risk-aware framework is proposed to activate and deactivate response policies. Hence, the success likelihood of the threat, and the cumulative impact of both of the threat and the response, are all considered.
Fichier principal
Vignette du fichier
paper.pdf (417.53 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00540839 , version 1 (29-11-2010)

Identifiants

  • HAL Id : hal-00540839 , version 1

Citer

Wael Kanoun, Nora Cuppens-Bouhlahia, Frédéric Cuppens, Samuel Dubus. Risk-aware framework for activating and deactivating policy-based response. NSS : IEEE International Conference on Network and System Security, Sep 2010, Melbourne, Australia. ⟨hal-00540839⟩
89 Consultations
332 Téléchargements

Partager

Gmail Facebook X LinkedIn More