A Vulnerability Risk Assessment Method Based on Heterogeneous Information Network

被引:9
|
作者
Wang, Wenrui [1 ]
Shi, Fan [1 ]
Zhang, Min [1 ]
Xu, Chengxi [1 ]
Zheng, Jinghua [1 ]
机构
[1] Natl Univ Def Technol, Coll Elect Engn, Hefei 230037, Peoples R China
关键词
Risk management; Measurement; Security; Computational modeling; Communication networks; Dispersion; Semantics; Common vulnerability scoring systems (CVSS); vulnerability; risk assessment; information fusion; heterogeneous information network;
D O I
10.1109/ACCESS.2020.3015551
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Due to the increasing number of network security vulnerabilities, vulnerability risk assessment must be performed to prioritize the repair of high-risk vulnerabilities. Traditional vulnerability risk assessment is based primarily on the Common Vulnerability Scoring Systems (CVSS) and attack graphs. Nevertheless, the CVSS metrics ignore the impact of the vulnerability on the specific network, which accounts that the identical vulnerability exists in different network environments is assigned repeated values. Additionally, the attack graphs still suffer from scalability and readability issues. To solve the above problems, a ranking method based on the heterogeneous information network is innovatively proposed to assess the vulnerability risk in a specific network. It considers the exploitability of a vulnerability, the impact of a vulnerability on the network components, and the importance of the vulnerable components. First, a heterogeneous information network containing vulnerability and host and the relationships between host and host is constructed to compute the risk score for each vulnerability and implement the ranking process. Second, a model extension method is proposed to adapt to situations in which additional factors related to vulnerability risk assessment need to be considered. Finally, we explore two case studies to compare the proposed method with CVSS and attack graph-based methods. The simulation results show that the proposed method can accurately assess the risk of vulnerabilities in a specific network environment and that it has a lower computational complexity than other methods.
引用
收藏
页码:148315 / 148330
页数:16
相关论文
共 50 条
  • [11] Network Situation Risk Assessment Based on Vulnerability Correlation Analysis
    Nan, Xinmeng
    Chen, Ruiqi
    Tian, Hongtao
    Liu, Yupeng
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON PROGRESS IN INFORMATICS AND COMPUTING (PIC), 2021, : 330 - 334
  • [12] A semantic network method for information system risk assessment
    Liu, Yi-Li
    Wu, Bing
    Journal of Beijing Institute of Technology (English Edition), 2010, 19 (SUPPL. 1): : 26 - 30
  • [13] Psychological assessment method based on heterogeneous graph network
    Jin Z.-G.
    Su R.-J.
    Zhao X.-F.
    Jilin Daxue Xuebao (Gongxueban)/Journal of Jilin University (Engineering and Technology Edition), 2024, 54 (04): : 1078 - 1085
  • [14] Vulnerability assessment method for manufacturing system based on complex network
    Gao G.
    Rong T.
    Yue W.
    Jisuanji Jicheng Zhizao Xitong/Computer Integrated Manufacturing Systems, CIMS, 2018, 24 (09): : 2288 - 2296
  • [15] Information Network Risk Assessment Based on AHP and Neural Network
    Su, Chunmei
    Li, Yonggang
    Mao, Wen
    Hu, Shangcheng
    2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SOFTWARE AND NETWORKS (ICCSN), 2018, : 227 - 231
  • [16] A method of road network vulnerability identification taking into account travelers' heterogeneous risk attitudes
    Lv, B.
    Zhang, J.
    Liu, Y. L.
    Huang, Y.
    SAFETY AND RELIABILITY - SAFE SOCIETIES IN A CHANGING WORLD, 2018, : 773 - 780
  • [17] THE VULNERABILITY ASSESSMENT METHOD OF RAILWAY NETWORK
    Wang Wei
    Liu Jun
    Li Haiying
    Jiang Xi
    PROCEEDINGS OF THE ASME JOINT RAIL CONFERENCE, VOL 1: RAILROAD INFRASTRUCTURE ENGINEERING SAFETY, SECURITY AND ENVIRONMENT, 2010, : 461 - 465
  • [18] An assessment method for highway network vulnerability
    El-Rashidy, Rawia Ahmed
    Grant-Muller, Susan M.
    JOURNAL OF TRANSPORT GEOGRAPHY, 2014, 34 : 34 - 43
  • [19] HRank: A Path Based Ranking Method in Heterogeneous Information Network
    Li, Yitong
    Shi, Chuan
    Yu, Philip S.
    Chen, Qing
    WEB-AGE INFORMATION MANAGEMENT, WAIM 2014, 2014, 8485 : 553 - 565
  • [20] Gear health assessment method based on heterogeneous information fusion
    Chen J.
    Chen X.
    Zheng D.
    Zhendong yu Chongji/Journal of Vibration and Shock, 2020, 39 (03): : 219 - 226