Journal of Communications, Vol 5, No 1 (2010), 71-80, Jan 2010
doi:10.4304/jcm.5.1.71-80

Optimal Security Patch Management Policies Maximizing System Availability

Toshikazu Uemura, Tadashi Dohi

Abstract


In this paper we quantitatively evaluate dependability/ security of a computer-based system subject to Denial of Service (DoS) attacks. More specifically, we develop two semi-Markov models for describing the stochastic behavior of systems with different security patch release strategies. The optimal security patch management policies are then formulated and analytically derived to maximize the steadystate system availability. We further perform the sensitivity analysis of model parameters through numerical experiments and refer to the effectiveness of our preventive patch management policies.



Keywords


Security evaluation, availability, patch management policy, semi-Markov model, analytical approach.

References



Full Text: PDF


Journal of Communications (JCM, ISSN 1796-2021)

Copyright @ 2006-2011 by ACADEMY PUBLISHER – All rights reserved.