IEEE Transactions on Reliability · 2019 · 22 citations · 32 references
EngineeringInformation SecuritySoftware EngineeringFault ToleranceSoftware AnalysisVulnerability Assessment (Computing)Modern Computer SystemsSystems EngineeringTrusted Operating SystemSystem VulnerabilitiesThreat (Computer)Intrusion ToleranceOperating System SecurityComputer EngineeringAttack VectorComputer ScienceData SecuritySoftware SecurityOperating SystemsProgram AnalysisSoftware TestingSecurity MeasurementSystem Software
This paper analyzes security problems of modern computer systems caused by vulnerabilities in their operating systems (OSs). Our scrutiny of widely used enterprise OSs focuses on their vulnerabilities by examining the statistical data available on how vulnerabilities in these systems are disclosed and eliminated, and by assessing their criticality. This is done by using statistics from both the National Vulnerabilities Database and the Common Vulnerabilities and Exposures System. The specific technical areas the paper covers are the quantitative assessment of forever-day vulnerabilities, estimation of days-of-grey-risk, the analysis of the vulnerabilities severity and their distributions by attack vector and impact on security properties. In addition, the study aims to explore those vulnerabilities that have been found across a diverse range of OSs. This leads us to analyzing how different intrusion-tolerant architectures deploying the OS diversity impact availability, integrity, and confidentiality.
32
System structure for software fault tolerance
Brian Randell · ACM SIGPLAN Notices · 1975 · 1.5K citations
The Honey Badger of BFT Protocols
Andrew Miller, Yu Xia, Kyle Croman et al. · 2016 · 773 citations
Cluster Computing, Blockchain Consensus Protocol, Engineering +19