Process-oriented security assessment of network services

Kewei Wang, Changzhen Hu, Chun Shan*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

With the development of information technology, more and more business processes and critical missions are delivered and implemented in the form of network services. Such networked processes have become the prime targets of intrusions and the focal point of cyber attack and defense. In analyzing the risk faced by these tasks and operations, existing process-oriented network service security assessment solutions fail to be accurate as they are still centered around system assets in nature. To fill this gap, in this paper, we propose a new process-oriented security assessment method of network services. First, we construct the mathematical model of network processes, which can be described as curves on Riemannian manifolds. We show that the geometry of the manifolds can be characterized through the pullbacks of Riemannian metrics by Neural Networks. Then, from the viewpoint of data, behavior, and objective, we propose consistency, reachability, and robustness, respectively, as the essential attributes in process-oriented security assessment. We also illustrate the detailed quantification of these attributes and the model of assessment. The proposed method is verified using a publicly available OpenStack dataset, and in a simulated distributed system. Experiment results validate the effectiveness of our approach and its superiority over current solutions.

Original languageEnglish
Article number111225
JournalComputer Networks
Volume264
DOIs
Publication statusPublished - Jun 2025
Externally publishedYes

Keywords

  • Differential geometry
  • Network processes
  • Neural networks
  • Security assessment
  • Security attributes

Fingerprint

Dive into the research topics of 'Process-oriented security assessment of network services'. Together they form a unique fingerprint.

Cite this

Wang, K., Hu, C., & Shan, C. (2025). Process-oriented security assessment of network services. Computer Networks, 264, Article 111225. https://doi.org/10.1016/j.comnet.2025.111225