RMIT University
Browse

Evaluating Security and Availability of Multiple Redundancy Designs when Applying Security Patches

conference contribution
posted on 2024-11-03, 14:39 authored by Mengmeng Ge, Huy Kim, Dong Seong Kim
In most of modern enterprise systems, redundancy configuration is often considered to provide availability during the part of such systems is being patched. However, the redundancy may increase the attack surface of the system. In this paper, we model and assess the security and capacity oriented availability of multiple server redundancy designs when applying security patches to the servers. We construct (1) a graphical security model to evaluate the security under potential attacks before and after applying patches, (2) a stochastic reward net model to assess the capacity oriented availability of the system with a patch schedule. We present our approach based on case study and model-based evaluation for multiple design choices. The results show redundancy designs increase capacity oriented availability but decrease security when applying security patches. We define functions that compare values of security metrics and capacity oriented availability with the chosen upper/lower bounds to find design choices that satisfy both security and availability requirements.

History

Start page

53

End page

60

Total pages

8

Outlet

Proceedings of the 47th Annual IEEE/IFIP International Conference on Dependable Systems and Networks Workshops (DSN-W 2017)

Name of conference

DSN-W 2017

Publisher

IEEE

Place published

United States

Start date

2017-06-26

End date

2017-06-29

Language

English

Copyright

© 2017 IEEE

Former Identifier

2006110130

Esploro creation date

2021-09-30

Usage metrics

    Scholarly Works

    Keywords

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC