A novel automatic severity vulnerability assessment framework

被引:2
作者
Wen, Tao [1 ]
Zhang, Yuqing [1 ,2 ]
Dong, Ying [2 ]
Yang, Gang [2 ]
机构
[1] State Key Laboratory of Integrated Services Networks, Xidian University, Xi’an
[2] National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing
关键词
ASVA; Information security; Text mining; Vulnerability; Vulnerability assessment; Vulnerability database;
D O I
10.12720/jcm.10.5.320-329
中图分类号
学科分类号
摘要
Security vulnerabilities play an important role in network security. With the development of the network and the increasing number of vulnerabilities, many Quantitative Vulnerability Assessment Standards (QVAS) was proposed in order to enable professionals to prioritize the most important vulnerabilities with limited energy. However, it is difficult to apply QVAS manually due to the large number of vulnerabilities and lack of information. In order to address these problems, an Automatic Security Vulnerability Assessment Framework (ASVA) is proposed, which can automatically apply any QVAS to special Vulnerability Databases. ASVA obtain values of the metrics of a QVAS with new features of Text Mining; assign these values to a formula of QVAS and finally compute the severity values of the vulnerabilities. New features proposed in ASVA are special combinations of metrics of QVAS, so that consider the influence of metrics each other and improve the accuracy of Text Mining. Based on ASVA, CVSS as a QVAS is applied to three representative Vulnerability Databases. The results show that ASVA reduces the cost and period of the application of QVAS and promotes the standardization of security vulnerability management. © 2015 Journal of Communications.
引用
收藏
页码:320 / 329
页数:9
相关论文
共 50 条
[31]   Coastal vulnerability to sea-level rise: a spatial–temporal assessment framework [J].
Oz Sahin ;
Sherif Mohamed .
Natural Hazards, 2014, 70 :395-414
[32]   Vulnerability of water systems: a comprehensive framework for its assessment and identification of adaptation strategies [J].
Stathatou, P. -M. ;
Kampragou, E. ;
Grigoropoulou, H. ;
Assimacopoulos, D. ;
Karavitis, C. ;
Porto, M. F. A. ;
Gironas, J. ;
Vanegas, M. ;
Reyna, S. .
DESALINATION AND WATER TREATMENT, 2016, 57 (05) :2243-2255
[33]   SEVA: A non-linear mathematical framework for climate change vulnerability assessment [J].
Tonmoy, F. N. ;
El-Zein, A. .
20TH INTERNATIONAL CONGRESS ON MODELLING AND SIMULATION (MODSIM2013), 2013, :2276-2282
[34]   Resilience-Vulnerability Analysis: A Decision-Making Framework for Systems Assessment [J].
Skondras, Nikolaos A. ;
Tsesmelis, Demetrios E. ;
Vasilakou, Constantina G. ;
Karavitis, Christos A. .
SUSTAINABILITY, 2020, 12 (22) :1-14
[35]   A Health Impact Assessment Framework for Assessing Vulnerability and Adaptation Planning for Climate Change [J].
Brown, Helen ;
Spickett, Jeffery ;
Katscherian, Dianne .
INTERNATIONAL JOURNAL OF ENVIRONMENTAL RESEARCH AND PUBLIC HEALTH, 2014, 11 (12) :12896-12914
[36]   Automatic segmentation of large power systems into fuzzy coherent areas for dynamic vulnerability assessment [J].
Kamwa, Innocent ;
Pradhan, Ashok Kumar ;
Joos, Geza .
IEEE TRANSACTIONS ON POWER SYSTEMS, 2007, 22 (04) :1974-1985
[37]   Incorporating Potential Severity into Vulnerability Assessment of Water Supply Systems under Climate Change Conditions [J].
Goharian, Erfan ;
Burian, Steven J. ;
Bardsley, Tim ;
Strong, Courtenay .
JOURNAL OF WATER RESOURCES PLANNING AND MANAGEMENT, 2016, 142 (02)
[38]   A Novel Centrality Measure for Network-wide Cyber Vulnerability Assessment [J].
Sathanur, Arun V. ;
Haglin, David J. .
2016 IEEE SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2016,
[39]   A novel network risk assessment method based on vulnerability correlation graph [J].
Liu Guqing ;
Wang Xintong ;
Yang Jungang ;
Kang Jie .
2014 IEEE WORKSHOP ON ELECTRONICS, COMPUTER AND APPLICATIONS, 2014, :31-34
[40]   Large language model based hybrid framework for automatic vulnerability detection with explainable AI for cybersecurity enhancement [J].
Basheer, Nihala ;
Islam, Shareeful ;
Alwaheidi, Mohammed K. S. ;
Mouratidis, Haralambos ;
Papastergiou, Spyridon .
INTEGRATED COMPUTER-AIDED ENGINEERING, 2025,