Software Diversity: Security, Entropy and Game Theory.

HotSec'12: Proceedings of the 7th USENIX conference on Hot Topics in Security(2012)

引用 8|浏览24
暂无评分
摘要
Although many have recognized the risks of software monocultures, it is not currently clear how much and what kind of diversity would be needed to address these risks. Here we attempt to provide insight into this issue using a simple model of hosts and vulnerabilities connected in a bipartite graph. We use this graph to compute diversity metrics as Renyi entropy and to formulate an anti-coordination game to understand why computer host owners would choose to diversify. Since security isn't the only factor considered when choosing software in the real world, we propose a slight variation of the popular security wargame Capture the Flag that can serve as a testbed for understanding the utility of diversity as a defense strategy.
更多
查看译文
关键词
diversity metrics,bipartite graph,popular security,software monocultures,Renyi entropy,anti-coordination game,computer host owner,defense strategy,real world,simple model,game theory,software diversity
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要