Process-oriented security assessment of network services

Kewei Wang, Changzhen Hu, Chun Shan*

*此作品的通讯作者

科研成果: 期刊稿件文章同行评审

1 引用 (Scopus)

摘要

With the development of information technology, more and more business processes and critical missions are delivered and implemented in the form of network services. Such networked processes have become the prime targets of intrusions and the focal point of cyber attack and defense. In analyzing the risk faced by these tasks and operations, existing process-oriented network service security assessment solutions fail to be accurate as they are still centered around system assets in nature. To fill this gap, in this paper, we propose a new process-oriented security assessment method of network services. First, we construct the mathematical model of network processes, which can be described as curves on Riemannian manifolds. We show that the geometry of the manifolds can be characterized through the pullbacks of Riemannian metrics by Neural Networks. Then, from the viewpoint of data, behavior, and objective, we propose consistency, reachability, and robustness, respectively, as the essential attributes in process-oriented security assessment. We also illustrate the detailed quantification of these attributes and the model of assessment. The proposed method is verified using a publicly available OpenStack dataset, and in a simulated distributed system. Experiment results validate the effectiveness of our approach and its superiority over current solutions.

源语言英语
文章编号111225
期刊Computer Networks
264
DOI
出版状态已出版 - 6月 2025
已对外发布

指纹

探究 'Process-oriented security assessment of network services' 的科研主题。它们共同构成独一无二的指纹。

引用此