Towards a Theory of Cyber Security Assessment in the Universal Composable Framework
In this paper, we propose a novel Cyber security assessment methodology is presented and analyzed based on the decomposition and composition mechanism. To evaluate the security of a Cyber system, we first decompose the entire system into a set of security primitives/functionalites (a decomposition procedure); and then evaluate individual implementation in the environment-based security framework (a security assessment procedure). Finally, a composition theorem is formalized and proved in the universally composable framework that supports the composition of security modules (individual functionalities composition procedure). The presented SA-framework has the following salient features: ·it introduces the concept of the virtual ideal security (over its operation environment) serving as the benchmark, which can flexibly define sets of security attributes over various operation environments. ·supported by the composition theory, it will result in a comprehensive multidimensional security metrics over the scope of the concerning security aspects; ·while reducing the complexity of the security assessment for information system significantly, it captures the dynamic nature of the adversary strategies over the particular operation environment; ·with its computational efficiency of being programmable in polynomial time toward a security attribute, it promises a foundation for the development of the future effective SA automation tools.
Huafei Zhu
Institute for Infocomm Research, A*STAR, Singapore
国际会议
Second International Symposium on Information Science and Engineering(第二届信息科学与工程国际会议)
上海
英文
203-207
2009-12-26(万方平台首次上网日期,不代表论文的发表时间)