【24h】

Using CVSS in Attack Graphs

机译:在攻击图中使用CVSS

获取原文

摘要

Derived from attack models, attack graphs are providing an efficient way to model attack scenarios intended against computer networks. Such graphs are using CVE database in which all known vulnerabilities are gathered. The CVSS framework is aiming to give numeric scores to each vulnerability recorded in the CVE database, which represent its characteristics and quantify its security impacts. In this paper we adapt attack graphs definition in order to be able to use them in conjunction with CVSS framework. The aim of our work is to provide a way to give an assessment of the impact of attacks on the hosts of the target network. This assessment is made using a host damage score and a network damage score, which take into account the characteristics and consequences of each atomic attack constituting an attack scenario.
机译:从攻击模型派生而来,攻击图提供了一种有效的方法来对旨在针对计算机网络的攻击方案进行建模。此类图使用的是CVE数据库,其中收集了所有已知漏洞。 CVSS框架旨在为CVE数据库中记录的每个漏洞提供数字评分,以表示其特征并量化其安全影响。在本文中,我们调整了攻击图的定义,以便能够将其与CVSS框架结合使用。我们工作的目的是提供一种评估攻击对目标网络主机的影响的方法。该评估是使用主机损害评分和网络损害评分进行的,这些评分考虑了构成攻击场景的每次原子攻击的特征和后果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号