首页> 外文会议>2018 International Conference on Advances in Big Data, Computing and Data Communication Systems >CVSS Metric-Based Analysis, Classification and Assessment of Computer Network Threats and Vulnerabilities
【24h】

CVSS Metric-Based Analysis, Classification and Assessment of Computer Network Threats and Vulnerabilities

机译:基于CVSS指标的计算机网络威胁和漏洞的分析,分类和评估

获取原文
获取原文并翻译 | 示例

摘要

This paper provides a Common Vulnerability Scoring System (CVSS) metric-based technique for classifying and analysing the prevailing Computer Network Security Vulnerabilities and Threats (CNSVT). The problem that is addressed in this paper, is that, at the time of writing this paper, there existed no effective approaches for analysing and classifying CNSVT for purposes of assessments based on CVSS metrics. The authors of this paper have achieved this by generating a CVSS metric-based dynamic Vulnerability Analysis Classification Countermeasure (VACC) criterion that is able to rank vulnerabilities. The CVSS metric-based VACC has allowed the computation of vulnerability Similarity Measure (VSM) using the Hamming and Euclidean distance metric functions. Nevertheless, the CVSS-metric based on VACC also enabled the random measuring of the VSM for a selected number of vulnerabilities based on the [Ma-Ma], [Ma-Mi], [Mi-Ci], [Ma-Ci] ranking score. This is a technique that is aimed at allowing security experts to be able to conduct proper vulnerability detection and assessments across computer-based networks based on the perceived occurrence by checking the probability that given threats will occur or not. The authors have also proposed high-level countermeasures of the vulnerabilities that have been listed. The authors have evaluated the CVSS-metric based VACC and the results are promising. Based on this technique, it is worth noting that these propositions can help in the development of stronger computer and network security tools.
机译:本文提供了一种基于通用漏洞评分系统(CVSS)度量的技术,用于对流行的计算机网络安全漏洞和威胁(CNSVT)进行分类和分析。本文要解决的问题是,在撰写本文时,还没有有效的方法可以基于CVSS度量对CNSVT进行分析和分类。本文的作者通过生成能够对漏洞进行排名的基于CVSS度量的动态漏洞分析分类对策(VACC)标准来实现这一目标。基于CVSS度量的VACC允许使用汉明和欧几里德距离度量功能来计算脆弱性相似性度量(VSM)。尽管如此,基于VACC的CVSS度量还可以基于[Ma-Ma],[Ma-Mi],[Mi-Ci],[Ma-Ci]排名对选定数量的漏洞进行VSM的随机测量。得分了。此技术旨在通过检查给定威胁是否会发生的可能性,使安全专家能够基于感知到的事件跨计算机网络进行适当的漏洞检测和评估。作者还提出了已列出漏洞的高级对策。作者评估了基于CVSS度量的VACC,结果令人鼓舞。基于此技术,值得注意的是,这些主张可以帮助开发更强大的计算机和网络安全工具。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号