Evaluating systems that keep running under attack

Two panels compared. Above, vertical bars spaced almost evenly along a time axis represent attacks assumed to arrive uniformly. Below, on the same axis, the bars form clusters separated by empty stretches, showing that attacks are actually bursty. To the right, four boxes represent a system with one filled grey, showing that it runs on despite a compromised part.

Some designs start from the premise that intrusion cannot be prevented entirely. An intrusion tolerant system is built so that the service as a whole continues even after an attacker takes over part of it.

The question is how to measure that resilience. Attacks arrive unpredictably, and they are not spread evenly: they concentrate in particular periods and arrive in correlated bursts.

This work represents attack arrivals with a Markovian arrival process, a description that captures both variability and correlation — the same tool we developed for analysing communication traffic. Embedding it in a model of an intrusion tolerant system allows availability and security measures to be evaluated quantitatively.

It shows that when attacks arrive in bursts, an evaluation assuming a simple Poisson process misjudges the risk.

Source paper

Quantitative Security Evaluation of Intrusion Tolerant Systems with Markovian Arrivals

IEEE Transactions on Reliability (2021)