[论文解读] Science of Cyber Security as a System of Models and Problems
本文通过将网络空间安全定义为对网络空间安全政策违规、攻击者与防御者工具以及网络动态之间关系的理论建模研究,提出了一套正式的科学框架,以恶意软件为核心实体,系统地推导出网络空间安全主要问题类别的分类体系。
Terms like "Science of Cyber" or "Cyber Science" have been appearing in literature with growing frequency, and influential organizations initiated research initiatives toward developing such a science even though it is not clearly defined. We propose to define the domain of the science of cyber security by noting the most salient artifact within cyber security -- malicious software -- and defining the domain as comprised of phenomena that involve malicious software (as well as legitimate software and protocols used maliciously) used to compel a computing device or a network of computing devices to perform actions desired by the perpetrator of malicious software (the attacker) and generally contrary to the intent (the policy) of the legitimate owner or operator (the defender) of the computing device(s). We further define the science of cyber security as the study of relations -- preferably expressed as theoretically-grounded models -- between attributes, structures and dynamics of: violations of cyber security policy; the network of computing devices under attack; the defenders' tools and techniques; and the attackers' tools and techniques where malicious software plays the central role. We offer a simple formalism of these key objects within cyber science and systematically derive a classification of primary problem classes within cyber science.
研究动机与目标
- 通过将恶意软件确定为核心实体,建立网络空间安全科学领域的清晰、正式定义。
- 将网络空间安全科学定义为对政策违规、攻击者/防御者工具与网络动态之间理论基础关系的系统研究。
- 基于所提出的模型框架,系统性地构建网络空间安全主要问题类别的分类体系。
- 为关键网络空间安全对象(如策略、攻击与防御)提供形式化表达,以支持严谨分析。
- 为成熟、理论驱动的网络空间安全科学奠定基础,解决当前缺乏连贯概念框架的问题。
提出的方法
- 围绕恶意软件及其在迫使系统违反政策中的作用,界定网络空间安全科学的核心领域。
- 引入一个正式的网络空间安全现象模型,涵盖攻击者、防御者与网络的属性、结构与动态特性。
- 形式化关键网络空间安全对象:策略、攻击(包括合法软件的滥用)、防御与网络配置。
- 通过系统分析模型组件及其相互作用,推导出主要问题类别的分类体系。
- 利用理论基础确保模型在多样化网络空间安全场景中具备可分析性与可推广性。
- 将形式化方法应用于识别并归类网络空间安全中的根本性挑战,如检测、预防与弹性。
实验结果
研究问题
- RQ1网络空间安全科学的核心领域是什么,如何对其进行正式定义?
- RQ2如何以理论为基础的方式建模攻击者与防御者工具、策略与网络动态之间的关系?
- RQ3从该正式模型中涌现出的网络空间安全主要问题类别有哪些?
- RQ4如何将恶意软件系统性地分析为网络空间安全现象中的核心实体?
- RQ5何种理论框架能够实现对网络空间安全问题的严谨、可重复的分类与研究?
主要发现
- 网络空间安全科学被正式定义为对政策违规、攻击者与防御者工具以及网络动态之间关系的研究,以恶意软件为核心实体。
- 从所提出的正式模型中系统推导出网络空间安全主要问题类别的分类体系。
- 该框架支持对网络空间安全现象的理论基础分析,超越了临时性或经验性方法。
- 形式化方法为建模攻击中使用的恶意软件与合法软件提供了基础,增强了模型的完备性。
- 该方法支持发展成熟、理论驱动的网络空间安全科学,解决了当前的概念与方法论空白。
- 该模型可推广至多样化网络空间安全场景,包括网络层攻击与策略执行挑战。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。