首页> 外文期刊>Computer Communications >Using the vulnerability information of computer systems to improve the network security
【24h】

Using the vulnerability information of computer systems to improve the network security

机译:利用计算机系统的漏洞信息来提高网络安全性

获取原文
获取原文并翻译 | 示例
           

摘要

In these years, the security problem becomes more important to everyone using computers. However, vulnerabilities on computers are found so frequently that system managers can not patch up all these vulnerabilities on hosts within the network in no time. They need to perform a risk evaluation in order to determine the priority of patching-up vulnerabilities. Besides, they may not have the administrator right on all hosts in the network, but only have the right on these network devices. To keep these vulnerabilities on hosts from exploitation, system managers can set the ACL scripts on network devices. The solution improves security in the network immediately, since some threatened service ports on hosts are blocked from accessed. This paper introduces a method to improve the network security, which consists of the network management, the vulnerability scan, the risk assessment, the access control, and the incident notification. Companioned to the network topology, the risk evaluation indicates the threatened service ports that should be blocked within ACL scripts. These procedures do not cost any extra hardware equipment. With the proposed method, the network security improves almost 40% with only 8% of threatened ports being blocked in the examined Class-B network. The 40% improvement of network security is evaluated with these two indices, the summary of CVSS values and the number of vulnerabilities in the network.
机译:这些年来,安全问题对于使用计算机的每个人都变得越来越重要。但是,计算机上的漏洞被发现的频率很高,以至于系统管理员无法立即修补网络中主机上的所有这些漏洞。他们需要执行风险评估,以确定修补漏洞的优先级。此外,他们可能没有对网络中所有主机的管理员权限,而仅对这些网络设备具有管理员权限。为了防止主机上的这些漏洞被利用,系统管理员可以在网络设备上设置ACL脚本。该解决方案可立即提高网络的安全性,因为阻止了主机上某些受威胁的服务端口的访问。本文介绍了一种提高网络安全性的方法,该方法包括网络管理,漏洞扫描,风险评估,访问控制和事件通知。与网络拓扑相对应,风险评估表明应在ACL脚本中阻止的受威胁服务端口。这些步骤无需花费任何额外的硬件设备。通过提出的方法,在检查的B类网络中,只有8%的受威胁端口被阻止,网络安全性提高了近40%。使用这两个指标(CVSS值摘要和网络中的漏洞数量)评估网络安全性提高40%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号