首页> 外文会议>Conference on Cyber Sensing >Risk Assessment by Dynamic Representation of Vulnerability, Exploitation, and Impact
【24h】

Risk Assessment by Dynamic Representation of Vulnerability, Exploitation, and Impact

机译:通过动态表示漏洞,利用和影响进行的风险评估

获取原文

摘要

Assessing and quantifying cyber risk accurately in real-time is essential to providing security and mission assurance in any system and network. This paper presents a modeling and dynamic analysis approach to assessing cyber risk of a network in real-time by representing dynamically its vulnerabilities, exploitations, and impact using integrated Bayesian network and Markov models. Given the set of vulnerabilities detected by a vulnerability scanner in a network, this paper addresses how its risk can be assessed by estimating in real-time the exploit likelihood and impact of vulnerability exploitation on the network, based on real-time observations and measurements over the network. The dynamic representation of the network in terms of its vulnerabilities, sensor measurements, and observations is constructed dynamically using the integrated Bayesian network and Markov models. The transition rates of outgoing and incoming links of states in hidden Markov models are used in determining exploit likelihood and impact of attacks, whereas emission rates help quantify the attack states of vulnerabilities. Simulation results show the quantification and evolving risk scores over time for individual and aggregated vulnerabilities of a network.
机译:实时准确评估和量化网络风险对于在任何系统和网络中提供安全性和任务保证至关重要。本文提出了一种建模和动态分析方法,通过使用集成的贝叶斯网络和马尔可夫模型动态表示网络的漏洞,利用和影响,从而实时评估网络的网络风险。给定网络中漏洞扫描程序检测到的一组漏洞,本文讨论了如何基于对网络的实时观察和评估,通过实时估计漏洞利用的可能性和对网络的影响来评估其风险。网络。使用集成的贝叶斯网络和马尔可夫模型可动态构建网络在漏洞,传感器测量和观测方面的动态表示。隐藏的马尔可夫模型中状态的出站和入站链接的转移率用于确定攻击的利用可能性和影响,而排放率有助于量化漏洞的攻击状态。仿真结果显示了针对网络的单个和聚合漏洞的量化和不断发展的风险评分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号