首页> 外文会议>IEEE Conference on Information and Communication Technology >Cyber Risk Assessment of Networked Cyber Assets using Probabilistic Model Checking
【24h】

Cyber Risk Assessment of Networked Cyber Assets using Probabilistic Model Checking

机译:使用概率模型检查网络网络资产的网络风险评估

获取原文

摘要

Attack path analysis to assess the path from the external facing entities to the inner hosts and network elements is a much researched problem. However, to compute a summary risk value per device, based on vulnerabilities discovered on a daily basis, is a much demanded capability in the arsenal of any security administrator of an enterprise network. Further, higher management such as CISOs have to be convinced with numerical risk comparisons to allow the down time required to patch the systems as opposed to defer it till a much later date during a scheduled shutdown. It must be noted that each security administrator's problem is different due to the difference in the structure and composition of the network they administer. Therefore, no industry data source can help in getting these numbers, as the risk numbers are specific to each network and its components. In this paper, we present a methodology based in probabilistic model checking to compute these risk scores for each device in an enterprise network.
机译:攻击路径分析以评估来自外部面对的实体到内部主机和网络元素的路径是一个很多研究的问题。但是,为了计算每个设备的摘要风险值,基于日常发现的漏洞,是企业网络的任何安全管理员的武器群岛中所要求的能力。此外,诸如CisoS的更高的管理必须相信数值风险比较,以允许修补系统所需的停机时间,而不是在预定的关闭期间将其推迟到稍后的日期。必须注意的是,由于他们管理的网络的结构和组成的差异,每个安全管理员的问题都不同。因此,没有行业数据源可以帮助获取这些数字,因为风险号是每个网络及其组件的特定。在本文中,我们提出了一种基于概率模型检查的方法,以计算企业网络中的每个设备的这些风险分数。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号