Improving Present Security through the Detection of Past Hidden Vulnerable States - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

Improving Present Security through the Detection of Past Hidden Vulnerable States

Résumé

Vulnerability assessment activities usually analyze new security advisories over current running systems. However, a system compromised in the past by a vulnerability unknown at that moment may still constitute a potential security threat in the present. Accordingly, past unknown system exposures are required to be taken into account. We present in this paper a novel approach for increasing the overall security of computing systems by identifying past hidden vulnerable states. In that context, we propose a modeling for detecting unknown past system exposures as well as an OVAL-based distributed framework for autonomously gathering network devices information and automatically analyzing their past security exposure. We also describe an implementation prototype and evaluate its performance through an extensive set of experiments.
Fichier principal
Vignette du fichier
Barrere-IM-2013.pdf (695.07 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00875199 , version 1 (21-10-2013)

Identifiants

  • HAL Id : hal-00875199 , version 1

Citer

Martín Barrère, Rémi Badonnel, Olivier Festor. Improving Present Security through the Detection of Past Hidden Vulnerable States. IFIP/IEEE International Symposium on Integrated Network Management (IM'13), May 2013, Ghent, Belgium. ⟨hal-00875199⟩
212 Consultations
95 Téléchargements

Partager

Gmail Facebook X LinkedIn More