首页> 外文期刊>IEEE transactions on dependable and secure computing >k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown Vulnerabilities
【24h】

k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown Vulnerabilities

机译:k-零日安全性:一种用于衡量未知漏洞风险的网络安全度量

获取原文
获取原文并翻译 | 示例

摘要

By enabling a direct comparison of different security solutions with respect to their relative effectiveness, a network security metric may provide quantifiable evidences to assist security practitioners in securing computer networks. However, research on security metrics has been hindered by difficulties in handling zero-day attacks exploiting unknown vulnerabilities. In fact, the security risk of unknown vulnerabilities has been considered as something unmeasurable due to the less predictable nature of software flaws. This causes a major difficulty to security metrics, because a more secure configuration would be of little value if it were equally susceptible to zero-day attacks. In this paper, we propose a novel security metric, $(k)$-zero day safety, to address this issue. Instead of attempting to rank unknown vulnerabilities, our metric counts how many such vulnerabilities would be required for compromising network assets; a larger count implies more security because the likelihood of having more unknown vulnerabilities available, applicable, and exploitable all at the same time will be significantly lower. We formally define the metric, analyze the complexity of computing the metric, devise heuristic algorithms for intractable cases, and finally demonstrate through case studies that applying the metric to existing network security practices may generate actionable knowledge.
机译:通过使不同安全解决方案相对于其相对有效性的直接比较,网络安全度量可以提供可量化的证据,以帮助安全从业人员保护计算机网络的安全。但是,由于难以处理利用未知漏洞的零日攻击,因此安全性指标研究受到阻碍。实际上,由于软件缺陷的可预测性较差,未知漏洞的安全风险已被认为无法衡量。这给安全度量带来了很大困难,因为如果安全配置同样容易受到零日攻击的影响,那么它的价值将很小。在本文中,我们提出了一种新颖的安全度量标准,$(k)$-零日安全性,以解决此问题。我们的指标不是尝试对未知漏洞进行排名,而是计算危害网络资产所需的此类漏洞数量;更大的数量意味着更高的安全性,因为同时拥有更多可用,适用和可利用的未知漏洞的可能性将大大降低。我们正式定义度量标准,分析计算度量标准的复杂性,为难处理的案例设计启发式算法,最后通过案例研究证明将度量标准应用于现有网络安全实践可能会产生可操作的知识。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号