首页> 外文OA文献 >Estimating Impact and Frequency of Risks to Safety and Mission Critical Systems Using CVSS
【2h】

Estimating Impact and Frequency of Risks to Safety and Mission Critical Systems Using CVSS

机译:使用CVss估算风险对安全和关键任务系统的影响和频率

摘要

Many safety and mission critical systems depend on the correct and secure operation of both supportive and core software systems. E.g., both the safety of personnel and the effective execution of core missions on an oil platform depend on the correct recording storing, transfer and interpretation of data, such as that for the Logging While Drilling (LWD) and Measurement While Drilling (MWD) subsystems. Here, data is recorded on site, packaged and then transferred to an on-shore operational centre. Today, the data is transferred on dedicated communication channels to ensure a secure and safe transfer, free from deliberately and accidental faults. However, as the cost control is ever more important some of the transfer will be over remotely accessible infrastructure in the future. Thus, communication will be prone to known security vulnerabilities exploitable by outsiders. This paper presents a model that estimates risk level of known vulnerabilities as a combination of frequency and impact estimates derived from the Common Vulnerability Scoring System (CVSS). The model is implemented as a Bayesian Belief Network (BBN).
机译:许多安全和关键任务系统都依赖于支持性和核心软件系统的正确和安全操作。例如,人员安全和在石油平台上有效执行核心任务都取决于正确的记录存储,传输和解释数据,例如随钻测井(LWD)和随钻测井(MWD)子系统的数据正确存储,传输和解释。在这里,数据被现场记录,打包并传输到陆上运营中心。如今,数据通过专用的通信通道进行传输,以确保安全可靠地传输,而不会出现故意和意外的故障。但是,由于成本控制越来越重要,因此将来某些转移将通过远程访问的基础架构进行。因此,通信将易于受到外部人员利用的已知安全漏洞。本文提出了一个模型,该模型通过从通用漏洞评分系统(CVSS)得出的频率和影响估算值的组合来估算已知漏洞的风险级别。该模型被实现为贝叶斯信念网络(BBN)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号