首页> 外文期刊>International Journal of Security and Networks >A model for quantitative security measurement and prioritisation of vulnerability mitigation
【24h】

A model for quantitative security measurement and prioritisation of vulnerability mitigation

机译:定量安全度量和漏洞缓解优先级排序的模型

获取原文
获取原文并翻译 | 示例
           

摘要

Quantitative security measurement is an essential step in managing security proactively. This measurement can help system administrator in making optimal decisions about mitigation of security risks posed by presence of vulnerabilities. Quantifying security risks using security metrics is an important and yet challenging task, as metrics exists for individual vulnerabilities but how to aggregate these metrics is still an unresolved issue. In this paper, we propose a quantitative security measurement model that measures security level of hosts in the network by aggregating risk levels of vulnerabilities in a meaningful manner. Further, proposed model guides system administrator in prioritising vulnerability mitigation by evaluating relative risk level of vulnerabilities in the network. Proposed model produces quantitative security metrics that provide rapid and consistent security measurement, hence aid in automated and reasonable security management. A case study is presented to demonstrate the efficacy of proposed model.
机译:定量安全度量是主动管理安全的重要步骤。此度量可以帮助系统管理员做出最佳决策,以减轻由于存在漏洞而造成的安全风险。使用安全度量标准量化安全风险是一项重要且具有挑战性的任务,因为存在针对单个漏洞的度量标准,但是如何汇总这些度量标准仍未解决。在本文中,我们提出了一种定量安全度量模型,该模型通过以有意义的方式汇总漏洞的风险级别来度量网络中主机的安全级别。此外,建议的模型通过评估网络中漏洞的相对风险级别,指导系统管理员确定漏洞缓解的优先级。提议的模型将产生定量的安全度量,这些度量可提供快速且一致的安全度量,从而有助于自动化和合理的安全管理。案例研究表明了所提出模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号