首页> 外文会议>International Conference on Information Assurance and Security >Quantitative penetration testing with item response theory
【24h】

Quantitative penetration testing with item response theory

机译:基于项目响应理论的定量渗透测试

获取原文

摘要

Existing penetration testing approaches assess the vulnerability of a system by determining whether certain attack paths are possible in practice. Thus, penetration testing has so far been used as a qualitative research method. To enable quantitative approaches to security risk management, including decision support based on the cost-effectiveness of countermeasures, one needs quantitative measures of the feasibility of an attack. Also, when physical or social attack steps are involved, the binary view on whether a vulnerability is present or not is insufficient, and one needs some viability metric. When penetration tests are performed anyway, it is very easy for the testers to keep track of, for example, the time they spend on each attack step. Therefore, this paper proposes the concept of quantitative penetration testing to determine the difficulty rather than the possibility of attacks based on such measurements. We do this by step-wise updates of expected time and probability of success for all steps in an attack scenario. In addition, we show how the skill of the testers can be included to improve the accuracy of the metrics, based on the framework of item response theory (Elo ratings). We prove the feasibility of the approach by means of simulations, and discuss application possibilities.
机译:现有的渗透测试方法通过确定某些攻击路径在实践中是否可行来评估系统的脆弱性。因此,到目前为止,渗透测试已被用作定性研究方法。为了实现安全风险管理的定量方法,包括基于对策成本效益的决策支持,人们需要对攻击可行性进行定量测量。另外,当涉及物理或社会攻击步骤时,关于是否存在漏洞的二进制视图是不够的,并且需要一些生存力度量。无论如何进行渗透测试时,测试人员很容易掌握例如在每个攻击步骤上花费的时间。因此,本文提出了定量渗透测试的概念来确定难度,而不是基于此类测量来确定攻击的可能性。我们通过逐步更新攻击场景中所有步骤的预期时间和成功概率来做到这一点。此外,我们展示了如何基于项目响应理论(Elo评分)的框架来包括测试人员的技能,以提高度量的准确性。我们通过仿真证明了该方法的可行性,并讨论了应用可能性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号