Szczegóły publikacji

Opis bibliograficzny

A methodology for quantitative security evaluation of operating systems: scenario-based comparison of Qubes OS and Windows 11 / Artur Kapera, Marcin NIEMIEC // Electronics [Dokument elektroniczny]. — Czasopismo elektroniczne ; ISSN  2079-9292 . — 2026 — vol. 15 iss. 10 art. no. 2110, s. 1–30. — Wymagania systemowe: Adobe Reader. — Bibliogr. s. 28–30, Abstr. — Publikacja dostępna online od: 2026-05-14

Autorzy (2)

Słowa kluczowe

Qubes OSsecurityvirtual machineoperating systemvirtualizationXenGNU/Linuxmitre ATT&CKcompartmentalizationMicrosoft Windows

Dane bibliometryczne

ID BaDAP167877
Data dodania do BaDAP2026-06-02
Tekst źródłowyURL
DOI10.3390/electronics15102110
Rok publikacji2026
Typ publikacjiartykuł w czasopiśmie
Otwarty dostęptak
Creative Commons
Czasopismo/seriaElectronics

Abstract

Securing users’ endpoint devices is a highly important part of organizations’ overall security posture. The vast majority of cyber attacks either begin with endpoint compromise or use it as an effective method for lateral movement and privilege escalation. In this article we propose a new methodology for quantitatively assessing the overall security provided by operating systems, based on implemented mitigations of MITRE ATT&CK techniques. The proposed approach enables reproducible scenario-based comparisons of operating system security and can support security-oriented decision-making in organizational endpoint protection strategies. Moreover, it allows for quantitative assessment of operating systems under specific cyber attack scenarios, expressed as collections of adversaries’ utilized ATT&CK techniques, facilitating comparison across multiple operating systems under identical scenarios. We apply this methodology to Qubes OS and Windows 11, showcasing measurable differences in how both operating systems mitigate cyber threats.