This paper proposes a model-based rejuvenation approach that embeds rejuvenation strategies into a stochastic attack-defense model aligned with the Cyber Kill Chain phases. It enables phase-aware reasoning to determine how system refreshes can effectively shorten attacker dwell time and reduce overall exposure. A continuous-time Markov chain (CTMC) jointly captures adversary progression and defender-triggered rejuvenation. The framework links system and service level objectives (SLO) to assess availability and security. Rejuvenation is treated as a timer optimization problem, looking for the refresh rates that satisfy SLO constraints while balancing risk reduction against refresh overhead. Grounded in the classical notion of rejuvenation as periodic return to a known-good state, the proposal demonstrates, through a numerical case study on SQL injection, that tuned timers can bound attacker opportunity windows and improve availability and security to meet system and service SLO.
ENFORCING SYSTEM AND SERVICE AVAILABILITY AND SECURITY BY REJUVENATION
Giacobbe M.Investigation
;Scarpa M.
Investigation
;Distefano S.Investigation
2026-01-01
Abstract
This paper proposes a model-based rejuvenation approach that embeds rejuvenation strategies into a stochastic attack-defense model aligned with the Cyber Kill Chain phases. It enables phase-aware reasoning to determine how system refreshes can effectively shorten attacker dwell time and reduce overall exposure. A continuous-time Markov chain (CTMC) jointly captures adversary progression and defender-triggered rejuvenation. The framework links system and service level objectives (SLO) to assess availability and security. Rejuvenation is treated as a timer optimization problem, looking for the refresh rates that satisfy SLO constraints while balancing risk reduction against refresh overhead. Grounded in the classical notion of rejuvenation as periodic return to a known-good state, the proposal demonstrates, through a numerical case study on SQL injection, that tuned timers can bound attacker opportunity windows and improve availability and security to meet system and service SLO.Pubblicazioni consigliate
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


