A Survey on Network Security Hardening Models
Tito Waluyo Purboyo · 2013
In order to secure an organization's network assets, a network administrator must determine how to harden the network. Network administrators are often faced with a more challenging problem since they have to work within a fixed budget which may be less than the minimum cost of system hardening. Their problem is how to select a subset of security hardening measures so as to be within the budget and yet minimize the residual damage to the system caused by not plugging all required security holes. To aid the decision-making process, network administrators may use attack graphs, which, through analysis, yield network hardening suggestions. Researchers have previously looked into the problem of determining if a given set of security hardening measures can effectively make a networked system secure. Many of them also addressed the problem of minimizing the total cost of implementing these hardening measures, given costs for individual measures. In this work, we survey a systematic approach to solve this problem by formulating it as a mathematical model.