Towards autonomic risk-aware security configuration

  • Mohammad Salim Ahmed
  • , Ehab Al-Shaer
  • , Mohamed Mahmoud Taibah
  • , Muhammad Abedin
  • , Latifur Khan

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

Security of a network depends on a number of dynamically changing factors. These include emergence of new vulnerabilities and threats, policy structure and network traffic. Due to the dynamic nature of these factors, identifying security metrics that measure objectively the quality of security configuration pose a major challenge. Moreover, this evaluation must be done dynamically to handle real time changes in the threat toward the network. In this paper, we extend our security metric framework [2] that identifies and quantifies objectively the most significant security risk factors, which include existing vulnerabilities, historical trend of vulnerabilities of remotely accessible services, prediction of potential vulnerabilities for any general network service and their estimated severity and finally propagation of an attack within the network. We have implemented this framework as a user-friendly tool called Risk based prOactive seCurity cOnfiguration maNAger (ROCONA) and showed how this tool simplifies security configuration management using risk measurement and mitigation.

Original languageEnglish
Title of host publicationNOMS 2008 - IEEE/IFIP Network Operations and Management Symposium
Subtitle of host publicationPervasive Management for Ubiquitous Networks and Services
Pages722-725
Number of pages4
DOIs
StatePublished - 2008
Externally publishedYes
EventNOMS 2008 - IEEE/IFIP Network Operations and Management Symposium: Pervasive Management for Ubiquitous Networks and Services - Salvador - Bahia, Brazil
Duration: 7 Apr 200811 Apr 2008

Publication series

NameNOMS 2008 - IEEE/IFIP Network Operations and Management Symposium: Pervasive Management for Ubiquitous Networks and Services

Conference

ConferenceNOMS 2008 - IEEE/IFIP Network Operations and Management Symposium: Pervasive Management for Ubiquitous Networks and Services
Country/TerritoryBrazil
CitySalvador - Bahia
Period7/04/0811/04/08

ASJC Scopus subject areas

  • Computer Networks and Communications
  • Information Systems

Fingerprint

Dive into the research topics of 'Towards autonomic risk-aware security configuration'. Together they form a unique fingerprint.

Cite this