首页> 外文会议>Americas conference on information systems >AVTCS-Eco Framework: An Approach to Attack Prediction and Vulnerability Assessment in a Cyber Ecosystem
【24h】

AVTCS-Eco Framework: An Approach to Attack Prediction and Vulnerability Assessment in a Cyber Ecosystem

机译:AVTCS-Eco框架:网络生态系统中的攻击预测和漏洞评估方法

获取原文

摘要

In the light of recent cyber-attacks, it has become imperative for organizations to predict breaches in an accurate and comprehensive manner. In this study, we assess the impact of the external environment as well as factors internal to the organization. We propose the AVICS-Eco Framework to (ⅰ) predict cyber-attacks in organizations, (ⅱ) assess critical vulnerabilities, (ⅲ) aid IS managers to plan security investments, and, (ⅳ) decide what to patch and when to patch. We validated our model using Partial Least Square Structural Equation Modelling. We have used CSI-FBI, Ponemon and Checkpoint Survey data from 1997 to 2015. As a recommendation, CTOs should be cautious with the vulnerable software of specific categories. We derived that software vendors need to prioritize patches on Networks before Operating Systems. Firewalls were found to be superior in comparison to anti-viruses. Finally, we found limited support for cybersecurity legal provisions as attack inhibitors in the United States.
机译:鉴于最近的网络攻击,组织必须以准确而全面的方式预测违规情况。在这项研究中,我们评估外部环境的影响以及组织内部的因素。我们建议使用AVICS-Eco框架来(ⅰ)预测组织中的网络攻击,(ⅱ)评估关键漏洞,(ⅲ)协助IS经理计划安全投资,以及(ⅳ)决定修补内容和修补时间。我们使用偏最小二乘结构方程建模对模型进行了验证。我们使用了1997年至2015年的CSI-FBI,Ponemon和Checkpoint Survey数据。作为建议,CTO应谨慎使用特定类别的易受攻击的软件。我们得出结论,软件供应商需要在操作系统之前优先考虑网络上的补丁程序。与防病毒软件相比,发现防火墙更胜一筹。最后,在美国,我们发现对网络安全法律规定的支持有限,成为攻击的抑制剂。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号