首页> 外文会议>IEEE International Conference on Cybernetics >Exploitability analysis using predictive cybersecurity framework
【24h】

Exploitability analysis using predictive cybersecurity framework

机译:利用预测网络安全框架的利用性分析

获取原文
获取外文期刊封面目录资料

摘要

Managing Security is a complex process and existing research in the field of cybersecurity metrics provide limited insight into understanding the impact attacks have on the overall security goals of an enterprise. We need a new generation of metrics that can enable enterprises to react even faster in order to properly protect mission-critical systems in the midst of both undiscovered and disclosed vulnerabilities. In this paper, we propose a practical and predictive security model for exploitability analysis in a networking environment using stochastic modeling. Our model is built upon the trusted CVSS Exploitability framework and we analyze how the atomic attributes namely Access Complexity, Access Vector and Authentication that make up the exploitability score evolve over a specific time period. We formally define a nonhomogeneous Markov model which incorporates time dependent covariates, namely the vulnerability age and the vulnerability discovery rate. The daily transition-probability matrices in our study are estimated using a combination of Frei's model & Alhazmi Malaiya's Logistic model. An exploitability analysis is conducted to show the feasibility and effectiveness of our proposed approach. Our approach enables enterprises to apply analytics using a predictive cyber security model to improve decision making and reduce risk.
机译:管理安全性是一个复杂的过程,网络安全度量领域的现有研究提供了有限的深入了解对企业整体安全目标的影响。我们需要一代新一代指标,可以使企业更快地反应,以便在两个未被发现和披露的漏洞中正确保护关键任务系统。在本文中,我们提出了一种使用随机造型中网络环境中的利用性分析的实用和预测安全模型。我们的模型构建在可信CVSS利用性框架之上,我们分析了原子属性如何访问复杂性,访问载体和构成剥离性分数的身份验证在特定时间段内进化。我们正式定义了一个非均匀的马尔可夫模型,它包含时间依赖的协变量,即漏洞年龄和漏洞发现率。我们研究中的每日转换概率矩阵估计使用Frei模型和Alhazmi Malaiya的后勤模型的组合来估计。进行了利用性分析,以表明我们提出的方法的可行性和有效性。我们的方法使企业能够使用预测网络安全模型应用分析,以改善决策并降低风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号