【24h】

Dynamic Risk-Aware Patch Scheduling

机译:动态风险感知补丁计划

获取原文

摘要

Every month, many new software vulnerabilities are discovered and published which will pose security risks to power grid systems if they are exploited by attackers. Thus the vulnerabilities must be patched in a timely manner to reduce the chance of being exploited. However, not all vulnerabilities can be patched quickly due to limited security resources at many electric utility companies. This paper studies dynamic risk-aware patch scheduling to determine the order of patching vulnerabilities and minimize the security risk brought by vulnerabilities. We first predict the dynamic probability of exploit over time for each vulnerability and define a metric to compute the vulnerability’s dynamic risk based on the predicted probability. We then formulate two patch scheduling approaches. Evaluations on real datasets show high accuracy in predicting the dynamic probability of exploit and high effectiveness of our solutions in risk reduction compared with other scheduling methods.
机译:每个月都会发现并发布许多新的软件漏洞,如果这些漏洞被攻击者利用,将会给电网系统带来安全隐患。因此,必须及时修补漏洞,以减少被利用的机会。但是,由于许多电力公司的安全资源有限,并非所有漏洞都可以快速修复。本文研究动态风险感知补丁调度,以确定补丁漏洞的顺序,并最大程度地降低漏洞带来的安全风险。我们首先预测每个漏洞随时间推移的动态利用概率,然后根据预测的概率定义一个度量以计算漏洞的动态风险。然后,我们制定两种补丁调度方法。与其他调度方法相比,对真实数据集的评估显示出在预测动态利用概率方面的准确性,以及我们的解决方案在降低风险方面的高效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号