151
Views
15
CrossRef citations to date
0
Altmetric
Original Articles

Fault-tree modelling of computer system security

&
Pages 805-819 | Received 27 Apr 2004, Published online: 25 Jan 2007
 

Abstract

Quantitative assessment of the effect of security breaches on a computer system can be based on the following: specification of all foreseeable types of basic events and estimation of their probabilities of occurrence over a stated period of time; observation of the various types of security measures employed by the system; definition of the undesired top events resulting from security breaches, and estimation of the system’s vulnerability to each of these events as the cost incurred by the system if that event took place; mathematical modelling of the logical relations between the aforementioned entities. In this paper we adapt the fault-tree methodology of reliability engineering to the quantification of security exposure of computer systems. In this new context, a fault tree can be described as a logic diagram whose input represents breach events at various system levels, and whose vertices represent logic operations or gates. The root or output of the fault tree can be any of the undesired top events. We briefly survey algorithms for converting the switching (Boolean) expression of the indicator variable for the top event into a probability expression. Once the top event probability is determined, it can be multiplied by the system’s vulnerability to that event to yield a quantified value of the system’s exposure to it. We also handle the doubly stochastic problem of estimating the uncertainty in the top event probability by using an analytic exact formula relating the variance of the top event probability to the variances of the basic event probabilities. An example of a typical computer system is presented wherein numerical estimates are obtained for the top event probabilities and their variances and for the importance ranking of the various breach events.

Log in via your institution

Log in to Taylor & Francis Online

PDF download + Online access

  • 48 hours access to article PDF & online version
  • Article PDF can be downloaded
  • Article PDF can be printed
USD 61.00 Add to cart

Issue Purchase

  • 30 days online access to complete issue
  • Article PDFs can be downloaded
  • Article PDFs can be printed
USD 1,129.00 Add to cart

* Local tax will be added as applicable

Related Research

People also read lists articles that other readers of this article have read.

Recommended articles lists articles that we recommend and is powered by our AI driven recommendation engine.

Cited by lists all citing articles based on Crossref citations.
Articles with the Crossref icon will open in a new tab.