首页> 外文会议>International Conference on Knowledge-Based Engineering and Innovation >A novel system for quantifying the danger degree of computer network attacks
【24h】

A novel system for quantifying the danger degree of computer network attacks

机译:一种量化计算机网络攻击危险程度的新颖系统

获取原文

摘要

Nowadays, security improvement of computer networks is a serious issue. In order to do minimum cost network hardening, scoring vulnerabilities for finding the most dangerous ones is urgent. Standard efforts like CVSS rank vulnerabilities. But, CVSS has some weaknesses like, lack of suitable diversity for vulnerability scoring. Consequently, by using CVSS, vast number of vulnerabilities are mapped into only a small set of scores. On the other hand, CVSS is not capable of ranking multi-step attacks. So, CVSS is not applicable for discriminating vulnerabilities in real world. By regarding such challenges, in this paper, some attack graph based security metrics have been defined that makes risk assessment of multi-step attacks possible. As each vulnerability is evaluated based on its situation in the network beside its intrinsic features, scores diversity improves considerably. The most important innovation of our approach is its capability to do quantitative risk assessment instead of qualitatively one which has been achieved by defining security metrics as much as independent from CVSS.
机译:如今,提高计算机网络的安全性已成为一个严重的问题。为了进行最低成本的网络强化,必须对漏洞进行评分以找到最危险的漏洞。诸如CVSS之类的标准工作对漏洞进行排名。但是,CVSS具有一些弱点,例如,缺乏适当的多样性来进行漏洞评分。因此,通过使用CVSS,大量漏洞仅映射到一小部分分数中。另一方面,CVSS无法对多步攻击进行分级。因此,CVSS不适用于区分现实世界中的漏洞。通过考虑这些挑战,在本文中,已经定义了一些基于攻击图的安全度量,这使对多步攻击的风险评估成为可能。由于根据每个漏洞的本质特征以及网络中的情况来评估每个漏洞,因此分数的多样性得到了很大的改善。我们的方法最重要的创新是它能够进行定量风险评估,而不是定性评估,这是通过定义尽可能独立于CVSS的安全性指标而实现的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号