Title
A Large-Scale Study of the Time Required to Compromise a Computer System
Abstract
A frequent assumption in the domain of cybersecurity is that cyberintrusions follow the properties of a Poisson process, i.e., that the number of intrusions is well modeled by a Poisson distribution and that the time between intrusions is exponentially distributed. This paper studies this property by analyzing all cyberintrusions that have been detected across more than 260,000 computer systems over a period of almost three years. The results show that the assumption of a Poisson process model might be unoptimal - the log-normal distribution is a significantly better fit in terms of modeling both the number of detected intrusions and the time between intrusions, and the Pareto distribution is a significantly better fit in terms of modeling the time to first intrusion. The paper also analyzes whether time to compromise (TTC) increase for each successful intrusion of a computer system. The results regarding this property suggest that time to compromise decrease along the number of intrusions of a system.
Year
DOI
Venue
2014
10.1109/TDSC.2013.21
IEEE Trans. Dependable Sec. Comput.
Keywords
Field
DocType
intrusion detection,worms,trojan horses),pareto distribution,poisson distribution,time to compromise,stochastic processes,poisson process,frequent assumption,computer system,paper study,cyberintrusions,ttc,network management,log-normal distribution,cybersecurity,successful intrusion,large-scale study,risk management,better fit,invasive software (viruses,log normal distribution,poisson process model,exponential distribution,security of data,computational modeling,computer science,workstations,malware,statistical distributions
Pareto distribution,Computer science,Algorithm,Stochastic process,Workstation,Network operations center,Probability distribution,Exponential distribution,Poisson distribution,Log-normal distribution,Statistics,Distributed computing
Journal
Volume
Issue
ISSN
11
1
1545-5971
Citations 
PageRank 
References 
8
0.45
22
Authors
1
Name
Order
Citations
PageRank
Hannes Holm119114.59