Continuous-Time Markov Models of Cyber Attacks for Evaluating the Time to Security Failure
Valeria F. Gorohova, Adil A. Kassenov, Alexey Anatol'evich Magazev, Ekaterina K. Titova · 2024
We consider continuous-time Markov models of attack process, in which attacks and defender's actions are simulated by Poisson point processes. The main focus of the study is on how to compute the mean time to security failure (MTTSF), an important security metric that describes the temporal aspects of the secure system behavior. In the stationary case, we describe an eigenvector method of solving the respective Kolmogorov equation and deduce a formula for computing MTTSF. Further, we consider a simple non-stationary case with one attack simulated by an inhomogeneous Poisson point process with the rate$\lambda(t)$that is a simple periodic function of time. We obtain an explicit expression for MTTSF for the limiting case when the security is absent, while for the general case we investigate this metric using numeric methods. It is shown that the nonstationarity influences MTTSF, especially if the frequency of$\lambda(t)$is small. In our opinion, this observation should be taken into account in quantifying cyber security of real-life information systems.