首页> 外文期刊>International Journal of Applied Engineering Research >An Enhanced Framework for Identification and Risks Assessment of Zero-Day Vulnerabilities
【24h】

An Enhanced Framework for Identification and Risks Assessment of Zero-Day Vulnerabilities

机译:一种增强的识别和风险评估零级漏洞的框架

获取原文
获取原文并翻译 | 示例
       

摘要

Nowadays highly-skilled attackers can find the vulnerabilities of many networked applications. Meanwhile, the risk of a data breach increases dramatically as a software or application vulnerability always remains without a patch. By exploiting such vulnerability (called zero-day), hackers gain entry to the target network and can steal sensitive data. It is challenging to detect zero-day with traditional defenses because signature information in zero-day attacks is unknown. Consequently, a novel security solution is required that will discover zero-day attacks and estimate the severity of identified zero-day vulnerability. In our previous work [1], we proposed an approch for discovery of unknown vulnerabilities. This paper enhances the previous approch by presenting a framework that constitutes an integrated approach for detection and prioritization (based on likelihood) of zero-days attacks. The proposed framework follows a probabilistic approach for identification of the zero-day attack path and further to rank the severity of identified zero-day vulnerability. It is a hybrid detection-based technique that detects unknown flaws present in the network that are not detected yet. To evaluate the performance of the proposed framework, we adopted it in the network environment of Vikram university campus, India. The framework is very promising as experimental results showed detection rate of 96% for zero-day attacks with 0.3% false positive rate.
机译:如今,高技能的攻击者可以找到许多联网应用程序的漏洞。同时,数据泄露的风险随着软件或应用程序漏洞而始终仍然没有补丁,数据泄露的风险急剧增加。通过利用此类漏洞(称为零日),黑客将进入目标网络并可窃取敏感数据。通过传统防御检测零点是挑战,因为零日攻击中的签名信息是未知的。因此,需要一种新的安全解决方案,即将发现零日攻击并估算已识别的零天漏洞的严重性。在我们之前的工作[1]中,我们提出了一个发现未知漏洞的批准。本文通过呈现构成零末攻击的综合方法的框架来增强先前的认可,该框架是用于检测和优先级的综合方法(基于似然)零天攻击。所提出的框架遵循概率的方法,用于识别零天攻击路径,进一步对确定的零天脆弱性的严重程度进行排名。它是一种基于混合检测的技术,其检测尚未检测到的网络中存在的未知缺陷。为了评估拟议框架的表现,我们在印度维克兰大学校园的网络环境中采用了它。该框架非常有前景,因为实验结果显示零日攻击的检出率为96%,效率为0.3%误率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号