【24h】

Vulnerability survival analysis: A novel approach to vulnerability management

机译:漏洞生存分析:漏洞管理的新方法

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Computer security vulnerabilities span across large, enterprise networks and have to be mitigated by security engineers on a routine basis. Presently, security engineers will assess their "risk posture" through quantifying the number of vulnerabilities with a high Common Vulnerability Severity Score (CVSS). Yet, little to no attention is given to the length of time by which vulnerabilities persist and survive on the network. In this paper, we review a novel approach to quantifying the length of time a vulnerability persists on the network, its time-to-death, and predictors of lower vulnerability survival rates. Our contribution is unique in that we apply the cox proportional hazards regression model to real data from an operational IT environment. This paper provides a mathematical overview of the theory behind survival analysis methods, a description of our vulnerability data, and an interpretation of the results.
机译:计算机安全漏洞遍布大型企业网络,并且必须由安全工程师定期加以缓解。当前,安全工程师将通过量化具有高通用漏洞严重性评分(CVSS)的漏洞数量来评估其“风险态势”。但是,几乎没有关注漏洞在网络上持续存在并生存的时间长度。在本文中,我们回顾了一种新颖的方法来量化漏洞在网络上持续存在的时间长度,其到达死亡的时间以及较低的漏洞生存率的预测因素。我们的贡献是独特的,因为我们将cox比例风险回归模型应用于来自运营IT环境的真实数据。本文提供了生存分析方法背后的理论的数学概述,对我们的漏洞数据的描述以及对结果的解释。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号