首页> 外文会议>IEEE Region 10 Conference >Augmenting MulVAL with automated extraction of vulnerabilities descriptions
【24h】

Augmenting MulVAL with automated extraction of vulnerabilities descriptions

机译:通过自动提取漏洞描述来增强MulVAL

获取原文

摘要

Network attack graphs are a type of analysis tool that can be used to determine the impact that security vulnerabilities have on the network. It is important, then, for attack graphs to be able to represent enough information to aid this analysis. Moreover, they must be able to handle and integrate new vulnerabilities that are being discovered by the security community. We developed a prototype tool that can parse vulnerability descriptions, as provided in the CVE, to retrieve relevant information for generating interaction rules that can be incorporated into an attack graph generation software. The tool is able to parse correctly about 88.15% of sampled CVEs. Such a tool allows for the attack graphs generated to be up-to-date with any recently discovered vulnerabilities. Furthermore, the additional information provided by the generated rules enable more information to be used and represented in attack graphs in a simpler fashion, facilitating smoother analyses.
机译:网络攻击图是一种分析工具,可用于确定安全漏洞对网络的影响。因此,重要的是,攻击图必须能够表示足够的信息以帮助进行此分析。此外,他们必须能够处理和集成安全社区发现的新漏洞。我们开发了一个原型工具,该工具可以解析CVE中提供的漏洞描述,以检索相关信息以生成可以并入攻击图生成软件的交互规则。该工具能够正确解析约88.15%的采样CVE。这种工具可以使生成的攻击图具有最新发现的漏洞。此外,由生成的规则提供的附加信息使更多信息可以以更简单的方式使用并在攻击图中表示,从而有助于更平滑的分析。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号