Design and implementation of a security evaluation method based on event injection

GuoPing Yan,Zhibo Wu,Da M. Zhou
2009-01-01
Abstract:With the development of networks, security of computer systems becomes more and more important. In this paper, a method of security evaluation is proposed, which is based on event injection of representative network attacks. The attacks are divided into four modes: resources depletion mode, theft of information mode, data-driven mode and information deceit mode. According to parameters which are inputted by users, the evaluating system generates event mode, carries out injection and then collects and analyzes results. Two evaluating measures are proposed: degree of satisfaction and rate of intrusive detection. These measures can be used to evaluate the delay of communications and intrusive detection capability of computer systems, so they provide a reference about dependability of system's security.
What problem does this paper attempt to address?