• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

Optimal security patch management tool design based on probabilistic modeling and analysis

Research Project

Project/Area Number 21K17742
Research Category

Grant-in-Aid for Early-Career Scientists

Allocation TypeMulti-year Fund
Review Section Basic Section 60070:Information security-related
Research InstitutionOsaka University (2022-2023)
Ritsumeikan University (2021)

Principal Investigator

Zheng Junjun  大阪大学, 大学院情報科学研究科, 特任助教(常勤) (80822832)

Project Period (FY) 2021-04-01 – 2024-03-31
Project Status Completed (Fiscal Year 2023)
Budget Amount *help
¥2,600,000 (Direct Cost: ¥2,000,000、Indirect Cost: ¥600,000)
Fiscal Year 2022: ¥1,300,000 (Direct Cost: ¥1,000,000、Indirect Cost: ¥300,000)
Fiscal Year 2021: ¥1,300,000 (Direct Cost: ¥1,000,000、Indirect Cost: ¥300,000)
Keywords耐侵入システム / 確率モデル / マルコフ再生過程 / 位相型近似 / 感度分析 / パッチ管理 / 空間信頼性 / 定常解析 / プル型セキュリティパッチ管理 / 定常アベイラビリティ / 信頼性評価 / マルコフ型到着過程 / セキュリティパッチ管理 / 情報セキュリティ
Outline of Research at the Start

本研究では,耐侵入システムの最適なパッチ適用戦略について検討する.システムの振る舞いを正確に表現するために,一般分布による状態遷移を含むマルコフ再生過程を用いてシステムのモデル化を行う.また,位相型近似によりマルコフ再生過程を解析する.数値解析によりシステムのセキュリティ評価とコスト評価の両方の観点から最適なパッチ適用タイミングを明らかにする.さらに,提案されたパッチ管理戦略に基づくパッチ管理ツールを開発する.

Outline of Final Research Achievements

This study focuses on developing an optimal security patch management tool for intrusion-tolerant systems using probabilistic models. The system behavior is modeled using Markov regenerative processes, and the optimal patch application timing is determined from both security and cost perspectives. Sensitivity analysis is conducted to optimize the system design by identifying parameters that significantly impact system reliability and performance. Additionally, deep learning techniques are employed to propose efficcient methods for malware detection and classification, enhancing system safety and availability. A hierarchical modeling approach is proposed for calculating performance measures for multi-state systems, enabling the determination of optimal patch application strategies from various performance perspectives. This study strengthened the theoretical foundation of intrusion-tolerant systems and marked a significant step towards practical implementation.

Academic Significance and Societal Importance of the Research Achievements

本研究は,耐侵入システムの理論的基盤を強化し,最適なセキュリティパッチ管理を実現するための新しいアプローチを提供した点で学術的意義がある.確率モデルと深層学習を組み合わせることで,システムの信頼性と安全性を向上させる手法を確立した.また、これによりシステム管理者がより効率的にセキュリティパッチを適用できるようになり,サイバー攻撃に対する防御力が向上する社会的意義も大きい.実用化に向けた重要なステップを踏み出した本研究は,セキュリティ技術の発展に寄与している.

Report

(4 results)
  • 2023 Annual Research Report   Final Research Report ( PDF )
  • 2022 Research-status Report
  • 2021 Research-status Report
  • Research Products

    (17 results)

All 2024 2023 2022 2021 Other

All Int'l Joint Research (1 results) Journal Article (5 results) (of which Int'l Joint Research: 1 results,  Peer Reviewed: 5 results,  Open Access: 1 results) Presentation (9 results) (of which Int'l Joint Research: 5 results) Book (2 results)

  • [Int'l Joint Research] Duke University(米国)

    • Related Report
      2021 Research-status Report
  • [Journal Article] On the sensitivity of stationary solutions of Markov regenerative processes2024

    • Author(s)
      JunjunZheng, Hiroyuki Okamura, Tadashi Dohi
    • Journal Title

      Performance Evaluation

      Volume: 164 Pages: 102397-102397

    • DOI

      10.1016/j.peva.2024.102397

    • Related Report
      2023 Annual Research Report
    • Peer Reviewed
  • [Journal Article] 深層学習のソフトウェア信頼性とサイバーセキュリティへの応用2023

    • Author(s)
      李晨, 鄭俊俊
    • Journal Title

      オペレーションズ・リサーチ

      Volume: 5 Pages: 250-258

    • Related Report
      2023 Annual Research Report
    • Peer Reviewed
  • [Journal Article] Sensitivity analysis for a Markov regenerative software rejuvenation model2022

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Journal Title

      Stochastic Models

      Volume: - Pages: 1-28

    • DOI

      10.1080/15326349.2022.2117195

    • Related Report
      2022 Research-status Report
    • Peer Reviewed
  • [Journal Article] Quantitative Security Evaluation of Intrusion Tolerant Systems With Markovian Arrivals2021

    • Author(s)
      Zheng Junjun、Okamura Hiroyuki、Dohi Tadashi、Trivedi Kishor S.
    • Journal Title

      IEEE Transactions on Reliability

      Volume: 70 Issue: 2 Pages: 547-562

    • DOI

      10.1109/tr.2020.3026570

    • Related Report
      2021 Research-status Report
    • Peer Reviewed / Int'l Joint Research
  • [Journal Article] Availability Analysis of Software Systems with Rejuvenation and Checkpointing2021

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Journal Title

      Mathematics

      Volume: 9 Issue: 8 Pages: 846-846

    • DOI

      10.3390/math9080846

    • Related Report
      2021 Research-status Report
    • Peer Reviewed / Open Access
  • [Presentation] Hierarchical dependability modeling with multi-state systems2023

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi,
    • Organizer
      The 28th IEEE Pacific Rim International Symposium on Dependable Computing (PRDC 2023)
    • Related Report
      2023 Annual Research Report
    • Int'l Joint Research
  • [Presentation] On the interval reliability of intrusion tolerant systems using semi-Markov models2022

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      The 10th Asia-Pacific International Symposium on Advanced Reliability and Maintenance
    • Related Report
      2022 Research-status Report
    • Int'l Joint Research
  • [Presentation] A note on optimal pull-type security patch management policies for intrusion tolerant systems2022

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      電子情報通信学会信頼性研究会
    • Related Report
      2022 Research-status Report
  • [Presentation] A note on Interval Reliability Analysis of Intrusion Tolerant Systems Subject to DoS Attacks2022

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      電子情報通信学会信頼性研究会
    • Related Report
      2022 Research-status Report
  • [Presentation] An efficient transformer encoder-based classification of malware using API calls2022

    • Author(s)
      Chen Li, Zheng Chen, and Junjun Zheng
    • Organizer
      The 24th IEEE International Conference on High Performance Computing & Communications
    • Related Report
      2022 Research-status Report
    • Int'l Joint Research
  • [Presentation] Sensitivity Analysis of Software Rejuvenation Model with Markov Regenerative Process2021

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      2021 IEEE International Symposium on Software Reliability Engineering Workshops
    • Related Report
      2021 Research-status Report
    • Int'l Joint Research
  • [Presentation] Interval Reliability Analysis of Intrusion Tolerant Systems Subject to DoS Attacks2021

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      The 5th International Conference on Mathematical Techniques in Engineering Applications
    • Related Report
      2021 Research-status Report
    • Int'l Joint Research
  • [Presentation] A Note on Sensitivity Analysis of Software Rejuvenation Model with Markov Regenerative Process2021

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      電子情報通信学会信頼性研究会
    • Related Report
      2021 Research-status Report
  • [Presentation] A Note on Local Sensitivity Analysis of Stationary Solutions for Markov Regenerative Processes2021

    • Author(s)
      Junjun Zheng, jiahao Zhang, Hiroyuki Okamura, and Tadashi Dohi
    • Organizer
      電子情報通信学会信頼性研究会
    • Related Report
      2021 Research-status Report
  • [Book] Advances in Reliability and Maintainability Methods and Engineering Applications (Chapter 5: Sensitivity estimation of Markov reward models and its applications to component importance analysis)2023

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Total Pages
      30
    • Publisher
      Springer Nature
    • ISBN
      9783031288593
    • Related Report
      2023 Annual Research Report
  • [Book] Maintenance Management - Current Challenges, New Developments, and Future Directions (Chapter 5: Pull-type security patch management in intrusion tolerant systems: modeling and analysis) (G. Lambert-Torres et al., eds.)2023

    • Author(s)
      Junjun Zheng, Hiroyuki Okamura, and Tadashi Dohi
    • Total Pages
      20
    • Publisher
      IntechOpen
    • ISBN
      9781803564807
    • Related Report
      2022 Research-status Report

URL: 

Published: 2021-04-28   Modified: 2025-01-30  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi