透過您的圖書館登入
IP:18.217.210.147
  • 學位論文

考量危害事件與惡意攻擊下系統脆弱度最小化之近似最佳化冗餘配置策略

A Near-Optimal Redundancy Allocation Policy to Minimize System Vulnerability against Hazardous Events and Malicious Attacks

指導教授 : 林永松

摘要


現代組織企業越來越倚重資訊科技來協助日常的營運作業。然而,這樣的依賴性卻是建立在危害事件發生頻繁且惡意攻擊層出不窮的環境下,任何的綱路斷線或是機器故障都會造成嚴重的經濟損失。因此,為了達到持續性服務的目標,我們提出一個植基於冗餘配置的方法,期望將潛在威脅發生的可能性降到一個可以接受的程度。 在本論文中,我們將攻防雙方的戰役模擬成一個兩階的非線性整數規劃問題。在內層問題中 (ARS模型),攻擊者透過分配有限的攻擊能量來最大化網路元件面對危害事件的脆弱度。相反地,在外層問題中 (RAPMA模型),防守者嘗試在有限的預算限制下,透過冗餘元件的適當部署來最小化攻擊者所帶來的傷害。其中,我們發展一個以拉格蘭日鬆弛法為基礎的演算法來快速地解決此數學規劃問題。

並列摘要


Modern organizations have increasingly relied on information technology to facilitate daily business operations. However, the dependency is built upon an environment where hazardous events happen frequently and malicious attacks emerge in an endless stream. To attain the objective of “continuity of services”, we propose an approach based on redundancy allocation to reduce the possibility of threats occurring to an acceptable degree. In the thesis, we formulate a “battle” between the attacker and the network into a two-level programming problem. In the inner problem (ARS model) an attacker allocates the limited attack powers to maximize the vulnerability of network against hazardous events. Contrarily, in the outer problem (RAPMA model) a defender attempts to minimize the damages by deploying redundant components appropriately with the limited budgets. We develop a Lagrangean Relaxation-based algorithm to solve the programming problem efficiently.

參考文獻


[1] Wojciech Molisz, “Survivability Function ─ A Measure of Disaster-Based Routing Performance,” IEEE Journal on Selected Areas in Communication, vol. 22, no. 9, November 2004
[2] Howard F. Lipson, David A. Fish, “Survivability ─ A New Technical and Business Perspective on Security,” CERT ® Coordination Center Software Engineering Institute
[3] Benjamin B.M. Shao, “Optimal Redundancy Allocation for Information Technology Disaster Recovery in the Network Economy,” IEEE Transactions on Dependable and Secure Computing, Vol. 2, No.3, July-September 2005
[4] David W. Coit, Abdullah Konak, “Multiple Weighted Objectives Heuristic for the Redundancy Allocation Problem,” IEEE Transactions on Reliability, Vol. 55, No. 3 September 2006
[5] Jose E. Ramirez-Marquez, David W. Coit, Abdullah Konak, “Redundancy Allocation for series-parallel systems using a max-min approach,” IIE Transactions (2004) 36, 891-898

延伸閱讀