Evaluating systems that keep running under attack

Some designs start from the premise that intrusion cannot be prevented entirely. An intrusion tolerant system is built so that the service as a whole continues even after an attacker takes over part of it.
The question is how to measure that resilience. Attacks arrive unpredictably, and they are not spread evenly: they concentrate in particular periods and arrive in correlated bursts.
This work represents attack arrivals with a Markovian arrival process, a description that captures both variability and correlation — the same tool we developed for analysing communication traffic. Embedding it in a model of an intrusion tolerant system allows availability and security measures to be evaluated quantitatively.
It shows that when attacks arrive in bursts, an evaluation assuming a simple Poisson process misjudges the risk.
Source paper
Quantitative Security Evaluation of Intrusion Tolerant Systems with Markovian Arrivals
IEEE Transactions on Reliability (2021)