首页> 外文期刊>Future generation computer systems >Cybersecurity vulnerability mitigation framework through empirical paradigm: Enhanced prioritized gap analysis
【24h】

Cybersecurity vulnerability mitigation framework through empirical paradigm: Enhanced prioritized gap analysis

机译:通过经验范式缓解网络安全漏洞的框架:增强的优先差距分析

获取原文
获取原文并翻译 | 示例

摘要

Existing cybersecurity vulnerability assessment tools were designed based on the policies and standards defined by organizations such as the U.S. Department of Energy and the National Institute of Standards and Technology (NIST). Frameworks such as the cybersecurity capability maturity model (C2M2) and the NIST Cybersecurity Framework (CSF) are often used by the critical infrastructure owners and operators to determine the cybersecurity maturity of their facility. Although these frameworks are exceptional at performing qualitative cybersecurity analysis and identifying vulnerabilities, they do not provide a means to perform prioritized mitigation of those vulnerabilities in order to achieve a desired cybersecurity maturity. To address that challenge, we developed a framework and software application called the cybersecurity vulnerability mitigation framework through empirical paradigm (CyFEr). This paper presents the detailed architecture of CyFEr's enhanced prioritized gap analysis (EPGA) methodology and its application to CSF. The efficacy of the presented framework is demonstrated by comparing against existing similar models and testing against the cyber injects from a real-world cyber-attack that targeted industrial control systems (ICS) in critical infrastructures.
机译:现有的网络安全漏洞评估工具是根据美国能源部和美国国家标准与技术研究院(NIST)等组织定义的政策和标准设计的。关键基础架构所有者和运营商经常使用诸如网络安全能力成熟度模型(C2M2)和NIST网络安全框架(CSF)之类的框架来确定其设施的网络安全成熟度。尽管这些框架在执行定性网络安全分析和识别漏洞方面是出色的,但它们并未提供对这些漏洞进行优先缓解的手段,以实现所需的网络安全成熟度。为了应对这一挑战,我们开发了一个框架和软件应用程序,通过经验范式(CyFEr)来缓解网络安全漏洞。本文介绍了CyFEr增强型优先缺口分析(EPGA)方法的详细架构及其在CSF中的应用。通过与现有类似模型进行比较,并针对针对关键基础设施中的工业控制系统(ICS)的真实世界网络攻击中的网络注入进行测试,证明了所提出框架的有效性。

著录项

  • 来源
    《Future generation computer systems》 |2020年第4期|410-431|共22页
  • 作者

  • 作者单位

    Pacific Northwest National Laboratory Richland WA 99354 USA Engineering Sciences and Systems (Electrical and Computer Engineering) University of Arkansas Little Rock AR 99354 USA;

    Engineering Sciences and Systems (Electrical and Computer Engineering) University of Arkansas Little Rock AR 99354 USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Cybersecurity vulnerability assessment; Cybersecurity framework; Cybersecurity mitigation; Criteria ranking;

    机译:网络安全漏洞评估;网络安全框架;缓解网络安全;条件排名;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号