首页> 外文学位 >Quantifying the security risk of discovering and exploiting software vulnerabilities.
【24h】

Quantifying the security risk of discovering and exploiting software vulnerabilities.

机译:量化发现和利用软件漏洞的安全风险。

获取原文
获取原文并翻译 | 示例

摘要

Most of the attacks on computer systems and networks are enabled by vulnerabilities in a software. Assessing the security risk associated with those vulnerabilities is important. Risk models such as the Common Vulnerability Scoring System (CVSS), Open Web Application Security Project (OWASP) and Common Weakness Scoring System (CWSS) have been used to qualitatively assess the security risk presented by a vulnerability. CVSS metrics are the de facto standard and its metrics need to be independently evaluated.;In this dissertation, we propose using a quantitative approach that uses an actual data, mathematical and statistical modeling, data analysis, and measurement. We have introduced a novel vulnerability discovery model, Folded model, that estimates the risk of vulnerability discovery based on the number of residual vulnerabilities in a given software. In addition to estimating the risk of vulnerabilities discovery of a whole system, this dissertation has furthermore introduced a novel metrics termed time to vulnerability discovery to assess the risk of an individual vulnerability discovery.;We also have proposed a novel vulnerability exploitability risk measure termed Structural Severity. It is based on software properties, namely attack entry points, vulnerability location, the presence of the dangerous system calls, and reachability analysis. In addition to measurement, this dissertation has also proposed predicting vulnerability exploitability risk using internal software metrics.;We have also proposed two approaches for evaluating CVSS Base metrics. Using the availability of exploits, we first have evaluated the performance of the CVSS Exploitability factor and have compared its performance to Microsoft (MS) rating system. The results showed that exploitability metrics of CVSS and MS have a high false positive rate. This finding has motivated us to conduct further investigation. To that end, we have introduced vulnerability reward programs (VRPs) as a novel ground truth to evaluate the CVSS Base scores. The results show that the notable lack of exploits for high severity vulnerabilities may be the result of prioritized fixing of vulnerabilities.
机译:对计算机系统和网络的大多数攻击是由软件中的漏洞引起的。评估与这些漏洞相关的安全风险很重要。诸如通用漏洞评分系统(CVSS),开放Web应用程序安全项目(OWASP)和通用弱点评分系统(CWSS)之类的风险模型已用于定性评估漏洞所带来的安全风险。 CVSS指标是事实上的标准,需要对其指标进行独立评估。本文提出了一种使用实际数据,数学和统计模型,数据分析和测量的定量方法。我们引入了一种新颖的漏洞发现模型Folded模型,该模型根据给定软件中剩余漏洞的数量来估计漏洞发现的风险。除了估计整个系统的漏洞发现风险之外,本文还引入了一种新的度量标准,称为“漏洞发现时间”,以评估单个漏洞发现的风险。我们还提出了一种新颖的漏洞利用风险度量,称为“结构化”。严重程度。它基于软件属性,即攻击入口点,漏洞位置,危险系统调用的存在和可达性分析。除了测量,本文还提出了使用内部软件指标预测漏洞利用风险的方法。我们还提出了两种评估CVSS基本指标的方法。利用漏洞的可用性,我们首先评估了CVSS漏洞因子的性能,并将其性能与Microsoft(MS)评级系统进行了比较。结果表明,CVSS和MS的可利用性指标具有较高的误报率。这一发现促使我们进行了进一步的调查。为此,我们引入了漏洞奖励计划(VRP)作为评估CVSS基本分数的新颖基础。结果表明,针对高严重性漏洞的明显利用漏洞可能是由于优先解决漏洞所致。

著录项

  • 作者

    Mussa, Awad A Younis.;

  • 作者单位

    Colorado State University.;

  • 授予单位 Colorado State University.;
  • 学科 Computer science.
  • 学位 Ph.D.
  • 年度 2016
  • 页码 203 p.
  • 总页数 203
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号