On the assessment and metrics of the security of operating systems


On the assessment and metrics of the security of operating systems

Kuliamin V.V. (ISP RAS, Moscow, Russia; MSU, Moscow, Russia; NRU HSE, Moscow, Russia)
Petrenko A.K. (ISP RAS, Moscow, Russia; MSU, Moscow, Russia; NRU HSE, Moscow, Russia)

Abstract

Along with the tasks of ensuring the security of software systems and the study of methods for analyzing correctness and resistance to malicious influences, the tasks of evaluating and comparing the degree of security of software systems arise. In the general formulation, these tasks probably do not have a solution that would be recognized and would have practical benefits. It can be practically useful to formulate a problem where the class of comparable systems is narrowed down and potential scenarios for using appropriate metrics and evaluation methods are outlined. This article offers an approach to the development of methods for assessing the security of operating systems as a software product and examines some scenarios for their use. The proposed approach is essentially a taxonomy for the subject area of problems, methods and means of protecting operating systems, that is, it offers qualitative rather than quantitative assessments, however, the presence of a sufficiently complete and well-structured taxonomy greatly simplifies the development of quantitative metrics, as shown in recent publications cited in the review.

Keywords

secure operating systems; secure software development processes; OS architectures; hardening.

Edition

Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 67-80

ISSN 2220-6426 (Online), ISSN 2079-8156 (Print).

DOI: 10.15514/ISPRAS-2026-38(4)-19

For citation

Kuliamin V.V., Petrenko A.K. On the assessment and metrics of the security of operating systems. Proceedings of the Institute for System Programming, vol. 38, issue 4, part 2, 2026, pp. 67-80 DOI: 10.15514/ISPRAS-2026-38(4)-19.

Full text of the paper in pdf (in Russian) Back to the contents of the volume