Novel Security Metrics for Ranking Vulnerabilities in Computer Networks

被引:0
作者
Keramati, Marjan [1 ]
Keramati, Mahsa [2 ]
机构
[1] Semnan Univ, Dept Comp Sci, Semnan, Iran
[2] Univ Tehran, Dept Comp Engn, Tehran, Iran
来源
2014 7TH INTERNATIONAL SYMPOSIUM ON TELECOMMUNICATIONS (IST) | 2014年
关键词
Network hardening; Vulnerability; Exploit; CVSS; Attack Graph; Security Metric;
D O I
暂无
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
by daily increasing appearance of vulnerabilities and various ways of intruding networks, one of the most important fields in network security will be doing network hardening and this can be possible by patching the vulnerabilities. But this action for all vulnerabilities may cause high cost in the network and so, we should try to eliminate only most perilous vulnerabilities of the network. CVSS itself can score vulnerabilities based on amount of damage they incur in the network but the main problem with CVSS is that, it can only score individual vulnerabilities without considering its relationship with other vulnerabilities of the network. So, in order to help fill this gap, in this paper we have defined some Attack graph and CVSS-based security metrics that can help us to prioritize vulnerabilities in the network by measuring the probability of exploiting them and also the amount of damage they will impose on the network. Proposed security metrics are defined by considering interaction between all vulnerabilities of the network. So our method can rank vulnerabilities based on the network they exist in. Results of applying these security metrics on one well-known network example are also shown that can demonstrates effectiveness of our approach.
引用
收藏
页码:883 / 888
页数:6
相关论文
共 16 条
[1]  
Albanese M., 2012, P IEEE IFIP INT C DE
[2]  
[Anonymous], IEEE T DEPENDABLE SE
[3]  
[Anonymous], INT C COMP APPL IND
[4]  
Chen F, 2008, PROCEEDINGS OF THE INTERNATIONAL SYMPOSIUM ON ELECTRONIC COMMERCE AND SECURITY, P426, DOI 10.1109/ISECS.2008.122
[5]   Aggregating CVSS Base Scores for Semantics-Rich Network Security Metrics [J].
Cheng, Pengsu ;
Wang, Lingyu ;
Jajodia, Sushil ;
Singhal, Anoop .
2012 31ST INTERNATIONAL SYMPOSIUM ON RELIABLE DISTRIBUTED SYSTEMS (SRDS 2012), 2012, :31-40
[6]  
Feng Chen, 2010, Journal of Networks, V5, P543
[7]  
Gallon L., 2011, Proceedings of the Seventh International Conference on Signal-Image Technology & Internet-Based Systems (SITIS 2011), P24, DOI 10.1109/SITIS.2011.24
[8]  
Gallon L., 2011, 2011 Sixth International Conference on Availability, Reliability and Security, P59, DOI 10.1109/ARES.2011.18
[9]  
Islam T., 2008, 2008 NEW TECHNOLOGIE, P1
[10]  
Jaquith A., 2007, SECURITY METRICS REP