<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Scenario-Based Markovian Modeling of Web-System Availability Considering Attacks on Vulnerabilities</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Vyacheslav Kharchenko</string-name>
          <email>V.Kharchenko@khai.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yurij Ponochovny</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Artem Boyarchuk</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Anatoliy Gorbenko</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>National Aerospace University KhAI</institution>
          ,
          <addr-line>Kharkiv</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Poltava National Technical University named after Yurij Kondratyuk</institution>
          ,
          <addr-line>Poltava</addr-line>
          ,
          <country country="UA">Ukraine</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In the paper we simulate web-system availability taking into account security aspects and different maintenance scenarios. As a case study we have developed two Markov's models. These models simulate availability of a multitier web-system considering attacks on DNS vulnerabilities in additional to system failures due to hardware/software (HW/SW) faults. Proposed Markov's model use attacks rate and criticality as initial simulation parameters. In the paper we demonstrate how to estimate these parameters using open vulnerability databases (e.g. National Vulnerability Database). We also define different vulnerability elimination (VE) scenarios and examine how they affect system availability.</p>
      </abstract>
      <kwd-group>
        <kwd>web-system availability</kwd>
        <kwd>security</kwd>
        <kwd>vulnerability</kwd>
        <kwd>Markov's models</kwd>
        <kwd>scenario of vulnerability elimination</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>1 Introduction</p>
      <p>
        Efficient implementation and operation of multitier web-systems using COTS
components depend on accuracy of security assessment and quality of attacks
prevention and recovery activities. Security of web-system can be estimated by
analyzing web-components vulnerabilities and predicting attacks affecting system
availability and other security attributes. System availability and accessibility of the
provided ser-vices depend on the used maintenance strategy. This strategy can
implement various vulnerability prevention and elimination scenarios [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. Thus,
assessing web-systems availability taking into account both system failures due to
HW/SW faults, and hacker attacks on components vulnerabilities is important.
      </p>
      <p>
        To estimate system availability and security researchers develop various simulation
models [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. Most of them are based on attack tree analysis [
        <xref ref-type="bibr" rid="ref3 ref4">3,4</xref>
        ], Markov’s [
        <xref ref-type="bibr" rid="ref5 ref6">5,6</xref>
        ] and
semi-Markov’s chains [
        <xref ref-type="bibr" rid="ref7 ref8">7,8</xref>
        ] or use of Petri nets [
        <xref ref-type="bibr" rid="ref10 ref9">9,10</xref>
        ] as a mathematical apparatus.
However, known models do not explicitly consider attacks on system vulnerabilities
causing inaccessibility of the provided services (accessibility vulnerabilities) and do not
take into account different security policies and vulnerability elimination strategies.
      </p>
      <p>
        In the paper we analyze web-system availability considering failures caused by
HW/SW faults as well as attacks on system vulnerabilities. With this purpose we
propose and examine a set of Markov’s availability models implementing different
scenarios of vulnerability elimination. This paper continues research described in [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ]
using scenario-based approach.
      </p>
      <p>The rest of the paper is organized as follows. In the second section we suggest a set
of scenarios to assess web-system availability taking into account different vulnerability
elimination procedures. In the third section we discuss a technique of estimating input
parameters of Markov’s models by use of information about software component
vulnerabilities from the open vulnerability databases. The forth section presents a case
study and the set of Markov’s models and also examines simulation results.
2 The Scenario-Based Approach to
Modeling with Regards to System
Elimination</p>
    </sec>
    <sec id="sec-2">
      <title>Web-System Availability Vulnerabilities and their</title>
      <p>
        Attacks on vulnerabilities of web-systems can be simulated using Markov’s models
[
        <xref ref-type="bibr" rid="ref5 ref6 ref7">5-7</xref>
        ]. However, for that we should take into account that parameters of the
vulnerabilities (numbers and types) are changed as a result of elimination and patching
procedures.
      </p>
      <p>In the Fig. 1 we propose a set of common state-transitional models capturing
different attack and recovery scenarios. The scenarios are differed by a number of
attacked vulnerabilities: one (a-f) or several (g); with (b-g) or without (a) vulnerability
elimination; with vulnerability elimination after system been successfully attacked (b-d)
or during (e,f) preventive maintenance actions.</p>
      <p>We have marked model states as following: double circles correspond to up-states,
single line marked circles correspond to maintenance states, thick line marked circles
correspond to down-states after attacks.</p>
      <p>The simplest scenario is shown in Fig. 1,а. After successful attack a web-system is
recovered (e.g. rebooted) without vulnerability elimination. However not all attacks can
be successful and lead to web system unavailability. This is why we consider two
transitions from up-state S0: the first transition with the rate λattack*Da leads to down
(unavailable)-state Sd; the second one with the rate λattack*(1-Da) returns back to
upstate S0 (Da is a probability of attack to be successful).</p>
      <p>The second scenario (Fig. 1,b) illustrates vulnerability elimination during system
recovery after successful attack. We assume that during recovery action it is possible to
eliminate from 0 to all (nv) vulnerabilities. Hence, web-system may return from the
down-state Sd to the initial state S0 without vulnerability elimination with the rate
μ′a*(1-Dp), where Dp is a probability of successful recovery and vulnerability
elimination, or may transit to the next up-state Su with the rate μ′a*Dp.</p>
      <p>ilty
tuho lavo irae</p>
      <p>b
iw rem lvun
t
s
te
i
i
l
i
b
a
r
e
n
l
u
v
l
a
v
o
m
e
r
e
h
t
h
t
i
W
e
v
i
t
n
e
v
e
r
p
h
t
i
W
l
a
r
e
v
e
s
on se
s i
k it
ttaac ilrab
ith len
W vu
S0
S0
S0
S0
Sp
S0
Sp</p>
      <p>S0
Sd
Sd
Sd
Sd
Sd
Sd
Sd
Sd
Sd</p>
      <p>nv-1
Su
Su
Su
Su
Sp
Su</p>
      <p>Sp
Su
Sd
Sd
Sd</p>
      <p>Sd
Sd</p>
      <p>1
Su
Su
Su
Su
Sp
Su</p>
      <p>Sp
Sd</p>
      <p>Su</p>
      <p>Sd
Sd
Sd
Sd
Sd
Sd
0
Su
Su
Su
Su
Su
Su
a)
b)
c)
d)
e)
f)
g)</p>
      <p>The third scenario (Fig. 1,c) describes graduate vulnerability elimination only after
successful attacks on these vulnerabilities. In this scenario the total number of
vulnerabilities in the system may be unlimited nv → ∞.</p>
      <p>The step by step vulnerability elimination is described by the next scenario (Fig. 1,d).
In this case it is assumed that restart of web-system is possible without elimination of
vulnerability which was attacked.</p>
      <p>According with the fifth scenario (Fig. 1,e) vulnerabilities can be detected and
eliminated from the system only during the periodic maintenance actions (i.e. security
audits) only. After the successful attack a web-system is restarted or reboot without
vulnerability elimination. Vulnerabilities can be detected and eliminated from the
system only during periodic security audits. The probability of eliminating the i-th
vulnerability is equal to αi, Σαi = 1.</p>
      <p>The sixth scenario (Fig. 1,f) assumes that vulnerabilities can be detected and
eliminated from the system both after successful attacks or during periodic security
audits. The seventh scenario takes into account possibility of attacks on several
vulnerabilities (Fig. 1,g). The scenario describes sequential chains of attacks on sever-al
(four, in our example) services of a web-system. In this case an intruder continues to
attack the next services. After successful attack a web-system can transit to a new
upstate where vulnerabilities are eliminated from the system or can return back to the
initial state by system restarting or rebooting.</p>
      <p>Described set of scenarios is not complete. This set includes some basic scenarios.
However, other scenarios can be developed considering different procedures of
maintenance and vulnerability elimination or patching.
3 Estimation of Input Parameters for
Availability Models</p>
    </sec>
    <sec id="sec-3">
      <title>Markov’s</title>
    </sec>
    <sec id="sec-4">
      <title>Web-System</title>
      <sec id="sec-4-1">
        <title>3.1 Vulnerabilities Sampling</title>
        <p>In this section we discuss how parameters of Markov’s models simulating
websystem availability can be estimated using existing vulnerability databases like NVD.</p>
        <p>
          The whole set of vulnerabilities stored in NVD can be downloaded as an XML file
«NVD/CVE XML Feed with CVSS and CPE mappings (version 1.2)» [
          <xref ref-type="bibr" rid="ref11 ref12">11,12</xref>
          ]. Then we
need to select those vulnerabilities of Web-system components (DNS-server,
HTTPserver, application server, etc.) affecting system availability. It is can be done by
analyzing vulnerabilities availability impact and vector of access using, for instance,
common vulnerability scoring system (CVSS) [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ] provided by NVD:
        </p>
        <p>- Availability impact, A, which can be equal one of three fuzzy values “None” (N),
“Partial” (P) and “Complete” (C);
- Vector of access, value “Network” (N).</p>
        <p>For example, Table 1 presents a subset of vulnerabilities detected during 2013 and
causing unavailability of DNS (CVSS_vector – contains – AV:N, A:C и A:P;
ns1:descript – contains – DNS (an example for analysis attacks on DNS) including their
publishing dates and score.</p>
      </sec>
      <sec id="sec-4-2">
        <title>3.2 Estimation of Attack Rates</title>
        <p>In order to parameterizes state-transition models we need to evaluate a rate of the
attacks exploiting system vulnerabilities.</p>
        <p>This rate obviously depends on different factors including number of system
vulnerabilities, their criticality, availability impact and vector of access. However,
vulnerabilities define only the capability of a system to be attacked. On the other hand,
unlike random system failures, vulnerabilities are exploited by various intended (hacker,
computer criminals, industrial espionage, insiders, etc.) and unintended (viruses, worms,
malware, etc.) threat agents.</p>
        <p>Motivation of intended threat agents is also depended on the system itself (its value
and interest for the attacker). Last two factors are really difficult to define quantitatively.
Thus, in the paper we propose to define the attack rate by the average per year
frequency of vulnerability disclosure in the system components.</p>
        <p>Criticality of attack is determined as an average value of basic CVSS estimation. We
propose the following technique to estimate attack rate:</p>
        <p>1) development of availability block diagram (ABD) of web-systems as a
sequentially-parallel connection of components influencing on accessibility (similar to
RBD);
2) extraction from NVD the vulnerability subsets for all components of ABD;
3) calculation of average per year frequency of vulnerability disclosure in these
subsets;</p>
        <p>4) determination of attack rate as the maximum of these frequencies of vulnerability
disclosure;</p>
        <p>5) calculation of attack criticality as an average value of basic CVSS estimation for
selected set per year.</p>
        <p>According with Table 1, average attack rate on DNS vulnerabilities causing
unavailability could be estimated in 2013 as 1,26*10–3 1/h while the average criticality
equals 6,75.</p>
        <p>DNS</p>
        <sec id="sec-4-2-1">
          <title>DHCP</title>
        </sec>
        <sec id="sec-4-2-2">
          <title>Route</title>
          <p>DNS</p>
          <p>DHCP</p>
          <p>Route</p>
          <p>S0</p>
          <p>Models for Different Vulnerability
4.1 Initial Model and its Parameters</p>
          <p>Let us examine a web-system based on three network services: DNS, DHCP and
Routing. Reliability block diagram (RBD) and Markov’s model (the marked Markov’s
chain) of the web-system are shown in Fig. 2.</p>
          <p>
            The RBD consists of three consequently connected components and failure of any
components causes failure (unavailability) of the system. In this section we study two
availability models taking into account attacks on DNS vulnerabilities and different
maintenance operations including security audits [
            <xref ref-type="bibr" rid="ref7">7</xref>
            ]. The first model (MA-1)
corresponds to scenario with vulnerability elimination during security audits only
(Fig. 1,e). The second one (MA-2) implements scenario with vulnerability elimination
after successful attack on a system and also during security audits (Fig. 1,f).
          </p>
          <p>Initial values of model parameters are presented in Table 2. The models itself have
been implemented as Matlab programs.
4.2</p>
          <p>The Model MA-1</p>
          <p>This model describes a web-system with attacks on DNS vulnerabilities and
periodic maintenance activities (security audits) including detection and elimination
of vulnerabilities without complication of code (ladns =const).</p>
          <p>Marked Markov’s graph is shown on Fig. 3. As during these activities it is possible to
detect and eliminate more than one vulnerability [1…nv], we use a special parameter αj
which defines probability of detection of j-th (j  [1…nv]) vulnerabilities. Apparently,
Σαj = 1, and values α1, α2,… αj,… αnv are distributes on discreet law. For calculation
of geometrical distribution law αj was used with parameters: р=α1=0.7 (probability of
detection of the single vulnerability) and q=1–р=0.3 (Table 3).</p>
          <p>Initially (state S0) web-system works considering failures and recovering of DNS,
DHCP и Routing services (states S1- S3). After attack on DNS (transition to state S5
with the rate d1dns*laatdns) the system fails and can be recovered by restart without
vulnerability elimination with rate mureboot. Periodically maintenance activities are
performed (state S4) during which 0, 1,…nv vulnerabilities can be eliminated
(transitions from state S4 to states S0, S4… Sn). These transitions are weighted using
parameter αj*muprof. Further process is continued in the same way (states Sn…Sn+3).</p>
          <p>1</p>
          <p>The research results of availability function depending on parameters р=α1 and
mureboot are shown on Fig. 4 and Fig. 5.</p>
          <p>The greater value α1 causes more fast transition of the function A(t) to stationary
state (Fig. 4). A value of mureboot influences on a value of availability function
minimum, location of minimum on the time axis and time of transition to stationary
state (Fig. 5). If mureboot=2 (1/hour) availability function minimum equals 0,9953 for
t=17 hours; if mureboot=0.05 (1/hour) availability function minimum equals 0,9103 for
t=119 hours.
4.3</p>
          <p>The model МА-2</p>
          <p>This model describes scenarios whish in addition to MA-1 assumes detection and
elimination of vulnerabilities both during security audit and right after attack (without
complication of code (ladns =const). Marked Markov’s graph is shown on Fig. 6.</p>
          <p>S4</p>
          <p>After attack on DNS and transition to state S5 with rate d1dns*laatdns system fails
and can be recovered by restart without eliminating vulnerability with the rate (1–
d2p)*murecovery or with elimination with the rate d2p*murecovery.</p>
          <p>The results of availability function analysis depending on parameters d2p and laprof
are shown on Fig. 7 and Fig. 8. The increasing of probability of vulnerability
elimination d2 during maintenance activities causes more fast transition of the function
A(t) to stationary state (Fig. 8). Changing the availability function depending on the rate
of maintenance laprof is dual. On the one hand the rare maintenance activities are
carried on the more minimum of availability function on non-stationary phase. On the
other side the more often maintenance activities are carried on the faster the function
transits to stationary state (Fig. 8).
0.998
0.996
0.994
)0.992
t(
A
0.99
0.988
0.986</p>
          <p>The scenarios corresponding to the models MA-1 and MA-2 can be superposed to
increase availability due to increasing of minimum and duration of system transition
to the stationary state of availability function. To combine these two scenarios we
have developed a set of Matlab programs. Filing of coefficient matrixes was done
according with the same initial data (Table3). To solve systems of
KolmogorovChapman’s differential equations the method ode15s for time span [0…20000] hours.
The results of solving are shown on the Fig. 9.
0.998
0.996
0.994
0.992
)
t
(A0.99
0.988
0.986
0.984
МA-2
model without attacks
МA-1
combination of scenarios</p>
          <p>According to Fig. 9, the vulnerability elimination scenario MA-1 is better to use till
tswitch =750 hours, after this time the scenario MA-2 ensures better availability.
Hence at the beginning recovering a system after attack (without vulnerability
elimination) is preferable. Then, taking into account increase of the number of failures
caused by attacks other scenario (when vulnerabilities are detected and eliminated
both after attacks and during maintenance) becomes preferable. It allows increasing
the value of availability from 0.984 (MA-2) to 0.988 (MA-1) and decreasing time
transition to stationary state from 20000 (MA-1) to 3000 (MA-2) hours.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5 Conclusions</title>
      <p>We analyzed a set of web-system behavior scenarios in conditions of attacks on
component vulnerabilities. Quantitative assessment and research of availability for
such systems can be based on Markov’s models using statistic data about
vulnerabilities contained in open databases and described sequence of evaluating of
attacks rates and criticality.</p>
      <p>We proposed and discussed two models of web-system availability considering
attacks on DNS vulnerabilities and different scenarios of vulnerability elimination.
There is possibility and reasonability of scenario changing taking into account values
of availability function allowing increase minimum one at the non-stationary stage
and decrease time of transition to stationary state. This approach allows selecting VE
scenario to improve resilience of web-system.</p>
      <p>The future research efforts may be concentrated on development of integrated
strategies for maintenance and security policies selection taking into account physical,
design and interaction faults, and implementation of dynamically reconfigurable
weband cloud-systems with embedded monitor and solver to select the optimal strategy of
maintenance.</p>
      <p>Besides, other types of the vulnerabilities for confidentiality and integrity issues
and more detailed model taking into account routing processes can be researched.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>Dong</given-names>
            <surname>Seong</surname>
          </string-name>
          <string-name>
            <given-names>Kim</given-names>
            ,
            <surname>Machida</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Trivedi</surname>
          </string-name>
          ,
          <string-name>
            <surname>K.S.</surname>
          </string-name>
          :
          <article-title>Availability Modeling and Analysis of a Virtualized System</article-title>
          .
          <source>In: 15th IEEE Pacific Rim International Symposium on Dependable Computing</source>
          , pp.
          <fpage>365</fpage>
          --
          <lpage>371</lpage>
          , IEEE Press, Shanghai (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Zheng</surname>
            <given-names>Wu</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Yang</surname>
            <given-names>Ou</given-names>
          </string-name>
          , Yujun Liu:
          <article-title>A Taxonomy of Network and Computer Attacks Based on Responses</article-title>
          . In: International Conference on Information Technology, Computer Engineering and Management Sciences, pp.
          <fpage>26</fpage>
          -
          <lpage>29</lpage>
          , IEEE Press, Nanjing (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Roy</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          , Dong Seong Kim, Trivedi,
          <string-name>
            <surname>K.S.:</surname>
          </string-name>
          <article-title>Cyber security analysis using attack countermeasure trees</article-title>
          .
          <source>In: Proceedings of the Sixth Annual Workshop on Cyber Security and Information Intelligence Research (CSIIRW '10)</source>
          , pp.
          <fpage>1</fpage>
          --
          <lpage>4</lpage>
          , ACM, New York (
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Ping</surname>
            <given-names>Wang</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jia-Chi</surname>
            <given-names>Liu</given-names>
          </string-name>
          :
          <article-title>Threat Analysis of Cyber Attacks with Attack Tree+</article-title>
          .
          <source>Journal of Information Hiding and Multimedia Signal Processing</source>
          <volume>5</volume>
          (
          <issue>4</issue>
          ),
          <fpage>778</fpage>
          --
          <lpage>788</lpage>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <given-names>Alaa</given-names>
            <surname>Mohammed</surname>
          </string-name>
          Abdul-Hadi, Ponochovny,
          <string-name>
            <given-names>Y.</given-names>
            ,
            <surname>Kharchenko</surname>
          </string-name>
          ,
          <string-name>
            <surname>V.</surname>
          </string-name>
          :
          <article-title>Development of basic Markov's model research availability of commercial web services</article-title>
          .
          <source>Radioelectronic and computer systems (64)</source>
          ,
          <fpage>186</fpage>
          -
          <lpage>191</lpage>
          (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Kharchenko</surname>
            ,
            <given-names>V.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Alaa Mohammed</surname>
            Abdul-Hadi, Boyarchuk,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ponochovny</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          :
          <article-title>Web Systems Availability Assessment Considering Attacks on Service Configuration Vulnerabilities</article-title>
          . In: Zamojski,
          <string-name>
            <given-names>W.</given-names>
            ,
            <surname>Mazurkiewicz</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Sugier</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Walkowiak</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            ,
            <surname>Kacprzyk</surname>
          </string-name>
          ,
          <string-name>
            <surname>J</surname>
          </string-name>
          . (eds.)
          <source>Advances in Intelligent Systems and Computing</source>
          . vol.
          <volume>286</volume>
          , pp.
          <fpage>275</fpage>
          --
          <lpage>284</lpage>
          , Springer International Publishing,
          <string-name>
            <surname>Switzerland</surname>
          </string-name>
          (
          <year>2014</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Nicol</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sanders</surname>
            ,
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Trivedi</surname>
            ,
            <given-names>K.S.</given-names>
          </string-name>
          :
          <article-title>Model-based evaluation: from dependability to security</article-title>
          .
          <source>IEEE Transactions on Dependable and Secure Computing</source>
          <volume>1</volume>
          (
          <issue>1</issue>
          ),
          <fpage>48</fpage>
          -
          <lpage>65</lpage>
          (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Trivedi</surname>
            ,
            <given-names>K.S.</given-names>
          </string-name>
          , Dong Seong Kim, Roy,
          <string-name>
            <given-names>A.</given-names>
            ,
            <surname>Medhi</surname>
          </string-name>
          ,
          <string-name>
            <surname>D.</surname>
          </string-name>
          :
          <article-title>Dependability and security models</article-title>
          .
          <source>In: Proceedings 7th International Workshop on the Design of Reliable Communication Networks (DRCN</source>
          <year>2009</year>
          ), pp.
          <fpage>11</fpage>
          -
          <lpage>20</lpage>
          , IEEE Press, Washington, DC (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Kizza</surname>
            ,
            <given-names>J M.</given-names>
          </string-name>
          : Guide to Computer Network Security.
          <source>2nd edition</source>
          . Springer, London (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Al-Kuwaiti</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kyriakopoulos</surname>
            ,
            <given-names>N.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hussein</surname>
            ,
            <given-names>S.:</given-names>
          </string-name>
          <article-title>A comparative analysis of network dependability, fault-tolerence, reliability, security, and survivability</article-title>
          .
          <source>IEEE Communications Surveys &amp; Tutorials</source>
          <volume>11</volume>
          (
          <issue>2</issue>
          ),
          <fpage>106</fpage>
          --
          <lpage>124</lpage>
          (
          <year>2009</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>NVD - Advanced</surname>
            <given-names>Search</given-names>
          </string-name>
          , http://web.nvd.nist.gov/view/vuln/search-advanced
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>NVD - Data</surname>
            <given-names>Feeds</given-names>
          </string-name>
          , http://nvd.nist.gov/download.cfm#XML
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Recommendation</surname>
            <given-names>X.</given-names>
          </string-name>
          <year>1521</year>
          .
          <article-title>Common vulnerability scoring system</article-title>
          . ITU-T, Geneva, The
          <string-name>
            <surname>Switzerland</surname>
          </string-name>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>