首页> 外文期刊>Journal of systems and software >Quantifying security risk level from CVSS estimates of frequency and impact
【24h】

Quantifying security risk level from CVSS estimates of frequency and impact

机译:根据CVSS对频率和影响的估计来量化安全风险级别

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Modern society relies on and profits from well-balanced computerized systems. Each of these systems has a core mission such as the correct and safe operation of safety critical systems or innovative and effective operation of e-commerce systems. It might be said that the success of these systems depends on their mission. Although the concept of "well-balanced" has a slightly different meaning for each of these two categories of systems, both have to meet customer needs, deliver capabilities and functions according to expectations and generate revenue to sustain today's highly competitive market. Tighter financial constraints are forcing safety critical systems away from dedicated and expensive communication regimes, such as the ownership and operation of dedicated communication links, towards reliance on third parties and standardized means of communication. As a consequence, knowledge about their internal structures and operations is more widely and publicly available and this can make them more prone to security attacks. These systems are, therefore, moving towards a remotely exploitable environment and the risks associated with this must be controlled.rnRisk management is a good tool for controlling risk but it has the inherent challenge of quantitatively estimating frequency and impact in an accurate and trustworthy way. Quantifying the frequency and impact of potential security threats requires experience-based data which is limited and rarely reusable because it involves company confidential data. Therefore, there is a need for publicly available data sources that can be used in risk estimation. This paper presents a risk estimation model that makes use of one such data source, the Common Vulnerability Scoring System (CVSS). The CVSS Risk Level Estimation Model estimates a security risk level from vulnerability information as a combination of frequency and impact estimates derived from the CVSS. It is implemented as a Bayesian Belief Network (BBN) topology, which allows not only the use of CVSS-based estimates but also the combination of disparate information sources and, thus, provides the ability to use whatever risk information that is available. The model is demonstrated using a safety- and mission-critical system for drilling operational support, the Measurement and Logging While Drilling (M/LWD) system.
机译:现代社会依赖平衡良好的计算机系统并从中受益。这些系统中的每一个都有核心任务,例如安全关键系统的正确和安全操作或电子商务系统的创新和有效操作。可以说这些系统的成功取决于它们的任务。尽管“平衡”的概念对于这两类系统中的每一种都有稍微不同的含义,但是两者都必须满足客户需求,根据期望提供功能和功能,并产生收入以维持当今竞争激烈的市场。更加严格的财务约束迫使安全关键系统从专用和昂贵的通信机制(例如专用通信链路的所有权和运营)转向对第三方和标准化通信手段的依赖。因此,关于它们的内部结构和操作的知识可以更广泛地公开获得,这会使它们更容易受到安全攻击。因此,这些系统正朝着可远程利用的环境发展,因此必须控制与之相关的风险。风险管理是控制风险的良好工具,但它固有的挑战在于以准确和可信赖的方式定量估计频率和影响。量化潜在安全威胁的频率和影响需要基于经验的数据,该数据是有限的,并且很少重用,因为它涉及公司机密数据。因此,需要可用于风险估计的可公开获得的数据源。本文提出了一种风险评估模型,该模型使用了一个这样的数据源,即通用漏洞评分系统(CVSS)。 CVSS风险等级估计模型根据漏洞信息估计安全风险等级,作为从CVSS得出的频率和影响估计的组合。它以贝叶斯信任网络(BBN)拓扑的形式实现,不仅允许使用基于CVSS的估计,而且可以组合使用不同的信息源,因此可以使用任何可用的风险信息。使用安全和任务关键型系统(用于钻井操作支持),随钻测量和测井(M / LWD)系统来演示该模型。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号