Quantitative Assessment of Operational Security: Models and Tools
- Free/open
This approach is based on modeling the system as a privilege graph exhibiting operational security vulnerabilities and on
transforming this privilege graph into a Markov chain corresponding to all possible
successful attack scenarios. A set of tools has been developed to generate automatically the privilege graph of a Unix system, to transform it into the corresponding Markov chain and to compute characteristic measures of the operational system security.





