Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2017

Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options

Daniel Borbor
  • Fonction : Auteur
  • PersonId : 1022670
Lingyu Wang
  • Fonction : Auteur
  • PersonId : 1004175
Sushil Jajodia
  • Fonction : Auteur
  • PersonId : 978046

Résumé

The administrators of a mission critical network usually have to worry about non-traditional threats, e.g., how to live with known, but unpatchable vulnerabilities, and how to improve the network’s resilience against potentially unknown vulnerabilities. To this end, network hardening is a well-knowfn preventive security solution that aims to improve network security by taking proactive actions, namely, hardening options. However, most existing network hardening approaches rely on a single hardening option, such as disabling unnecessary services, which becomes less effective when it comes to dealing with unknown and unpatchable vulnerabilities. There lacks a heterogeneous approach that can combine different hardening options in an optimal way to deal with both unknown and unpatchable vulnerabilities. In this paper, we propose such an approach by unifying multiple hardening options, such as firewall rule modification, disabling services, service diversification, and access control, under the same model. We then apply security metrics designed for evaluating network resilience against unknown and unpatchable vulnerabilities, and consequently derive optimal hardening solutions that maximize security under given cost constraints.
Fichier principal
Vignette du fichier
453481_1_En_28_Chapter.pdf (1.17 Mo) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01684351 , version 1 (15-01-2018)

Licence

Paternité

Identifiants

Citer

Daniel Borbor, Lingyu Wang, Sushil Jajodia, Anoop Singhal. Securing Networks Against Unpatchable and Unknown Vulnerabilities Using Heterogeneous Hardening Options. 31th IFIP Annual Conference on Data and Applications Security and Privacy (DBSEC), Jul 2017, Philadelphia, PA, United States. pp.509-528, ⟨10.1007/978-3-319-61176-1_28⟩. ⟨hal-01684351⟩
104 Consultations
111 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More