A Policy-Based Vulnerability Analysis Framework

نویسندگان

  • Felix Wu
  • Sean Peisert
چکیده

Repeatability is essential to any science—computer science is no exception. However, the area of vulnerability analysis suffers from ambiguous definitions that hinder the repeatability of analysis results. Many researchers have turned to policy-based definitions of a vulnerability in an attempt to alleviate this ambiguity. However, it is rare that security policies are explicitly and precisely defined. As a result, these policy-based approaches merely shift the ambiguity from defining vulnerabilities to defining policies. Other researchers turn to strictly formal models and methods to provide repeatable results, but the practicality of such analysis is limited by the complexity of the environment and the availability of resources. This creates a conflict between repeatability and practicality that is often left unresolved in existing vulnerability analysis methods; an analysis framework either focuses on formal models to provide repeatability, or uses an ad hoc approach to provide practicality. This dissertation addresses this conflict by balancing specific formal and practical objectives to create a vulnerability analysis framework capable of producing repeatable results in realistic environments. This analysis framework relies on three major components: a hierarchy of security policies, a formal model of implementation vulnerabilities, and an implementation vulnerability classification scheme. We address the ambiguity surrounding security policies with a hierarchy that precisely defines security policies at four levels of abstraction. We use this policy hierarchy to provide a formal model of an implementation vulnerability. This model provides the formal foundation for our characteristic-based vulnerability classification scheme, which allows us to examine implementation vulnerabilities at a more practical level of abstraction. We combine these components into a cohesive implementation vulnerability analysis framework that provides insight into both when a system is non-secure, and how to mitigate that non-security.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Systematic Evaluation of Policy Strategies of the Vulnerability Reduction of the Sistan Plain to the Fluctuations and Water Scarcity

This study aimed to investigate the vulnerability of Sistan plain to fluctuations and Water Scarcity in Hirmand River using the vulnerability framework, by applying the resilience approach. The socioeconomic and biophysical components presented in this framework were embedded in a set of subsystems of the System Dynamics (SD) model. According to this, four levels of reference resilience were de...

متن کامل

Spatial Assessment of Regional Environmental Vulnerability for Environmental Planning in the Eastern Region of Urmia Lake

     Environment, development and sustainability are the three significant issues of worldwide concern. Environmental vulnerability and assessment of natural and anthropogenic activities impacts represent a comprehensive evaluation approach. The main purpose of this study is to present a comprehensive and novel framework in order to environmental vulnerability assessment using by spatial data a...

متن کامل

Evaluation of Ecological Vulnerability in Chelgard Mountainous Landscape

Although complexity and vulnerability assessment of mountain landscapes is increasingly taken into consideration, less attention is paid to ecophronesis-based solutions so as to reduce the fragile ecosystem vulnerability. The main propose of this study is to provide an insight of mountain complex landscape vulnerability and propose ecophronesis-based solutions in strategic planning framework fo...

متن کامل

Rapid Vulnerability Assessment of Lavizan Urban Forest Park

Although the vulnerability assessment of forest parks is used to determine the threats they face, a rapid and holistic framework has not been established well. The primary objective of this study is to adopt a framework for rapid assessment of forest parks vulnerability, examined in Lavizan forest park in Tehran (Iran) as the case study. The vulnerability assessment has been conducted, using th...

متن کامل

Rapid Vulnerability Assessment of Lavizan Urban Forest Park

Although the vulnerability assessment of forest parks is used to determine the threats they face, a rapid and holistic framework has not been established well. The primary objective of this study is to adopt a framework for rapid assessment of forest parks vulnerability, examined in Lavizan forest park in Tehran (Iran) as the case study. The vulnerability assessment has been conducted, using th...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010