【24h】

A Quantitative Measure of the Security Risk Level of Enterprise Networks

机译:企业网络安全风险等级的定量度量

获取原文
获取原文并翻译 | 示例

摘要

Along with the tremendous expansion of information technology and networking, the number of malicious attacks which cause disruption to business processes has concurrently increased. Despite such attacks, the aim for network administrators is to enable these systems to continue delivering the services they are intended for. Currently, many research efforts are directed towards securing network further whereas, little attention has been given to the quantification of network security which involves assessing the vulnerability of these systems to attacks. In this paper, a method is devised to quantify the security level of IT networks. This is achieved by electronically scanning the network using the vulnerability scanning tool (Nexpose) to identify the vulnerability level at each node classified according to the common vulnerability scoring system standards (critical, severe and moderate). Probabilistic approach is then applied to calculate an overall security risk level of sub networks and entire network. It is hoped that these metrics will be valuable for any network administrator to acquire an absolute risk assessment value of the network. The suggested methodology has been applied to a computer network of an existing UK organization with 16 nodes and a switch.
机译:随着信息技术和网络的迅猛发展,导致业务流程中断的恶意攻击数量同时增加。尽管存在此类攻击,但网络管理员的目标是使这些系统能够继续提供其预期的服务。当前,许多研究工作致力于进一步保护网络安全,而很少涉及网络安全的量化,这涉及评估这些系统对攻击的脆弱性。本文设计了一种量化IT网络安全级别的方法。这是通过使用漏洞扫描工具(Nexpose)对网络进行电子扫描,以识别根据常见漏洞评分系统标准(关键,严重和中等)分类的每个节点上的漏洞级别来实现的。然后应用概率方法来计算子网和整个网络的总体安全风险级别。希望这些度量标准对于任何网络管理员获取网络的绝对风险评估值都是有价值的。建议的方法已应用于具有16个节点和一个交换机的英国现有组织的计算机网络。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号