Software Vulnerability Patch Management with Semi-Markov Decision Process

نویسندگان

  • Chien-Cheng Huang
  • Kwo-Jean Farn
  • Feng-Yu Lin
  • Frank Yeong-Sung Lin
چکیده

Information security incidents frequency has been increasing dramatically, the aim of this study is to analyze the state-space reachability problems through the transition of vulnerable status after the informative system vulnerability exposure. In this research we took into consideration the time factor to analyze the arrival time to reachable states problem discussed in stochastic Petri nets. The mean arrival time and variance of the process between starting from an initial state and arriving at reachable states. We will therefore elaborate a novel model based on the semi-Markov stochastic Petri nets model for analyzing the period between the exposure of the vulnerability and the completion of its patch. We use the semi-Markov process to analyze the state-space reachability problems of the stochastic Petri nets, resulting in a novel model for software vulnerability patch management. Moreover, we include also the concept of discounted multi-objective semi-Markov decision process to obtain the total of the efficient extreme point set.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

A Semi-supervised Learning Framework for Decision Modeling of Software Project Management

Managing the decisions in organizations raises substantial challenges in regards of the associated processes. In software project management decision making has the critical role in this scenario since it defines the manager’s responsibilities and stems from the various sources linked to the process. The decision making constructs the essential foundation and thereby it needs a reliable framewo...

متن کامل

Availability analysis of mechanical systems with condition-based maintenance using semi-Markov and evaluation of optimal condition monitoring interval

Maintenance helps to extend equipment life by improving its condition and avoiding catastrophic failures. Appropriate model or mechanism is, thus, needed to quantify system availability vis-a-vis a given maintenance strategy, which will assist in decision-making for optimal utilization of maintenance resources. This paper deals with semi-Markov process (SMP) modeling for steady state availabili...

متن کامل

Vulnerability Disclosure and Software Provision

Internet Security, Vulnerability Disclosure and Software Provision* In this paper, we examine how software vulnerabilities affect firms that license software and consumers that purchase software. In particular, we model three decisions of the firm: (i) an upfront investment in the quality of the software to reduce potential vulnerabilities; (ii) a policy decision whether to announce vulnerabili...

متن کامل

Optimizing Red Blood Cells Consumption Using Markov Decision Process

In healthcare systems, one of the important actions is related to perishable products such as red blood cells (RBCs) units that its consumption management in different periods can contribute greatly to the optimality of the system. In this paper, main goal is to enhance the ability of medical community to organize the RBCs units’ consumption in way to deliver the unit order timely with a focus ...

متن کامل

Model-Building Adaptive Critics for Semi-Markov Control

Adaptive (or actor) critics are a class of reinforcement learning algorithms. Generally, in adaptive critics, one starts with randomized policies and gradually updates the probability of selecting actions until a deterministic policy is obtained. Classically, these algorithms have been studied for Markov decision processes under model-free updates. Algorithms that build the model are often more...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013