Effect of Security Controls on Patching Window: A Causal Inference based Approach

被引:4
作者
Kuppa, Aditya [1 ]
Aouad, Lamine [2 ]
Le-Khac, Nhien-An [1 ]
机构
[1] Univ Coll, Dublin, Ireland
[2] Tenable Corp, Columbia, MD USA
来源
36TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2020) | 2020年
关键词
Causal Inference; Security Controls; Patch Management; SELECTION;
D O I
10.1145/3427228.3427271
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In many organisations there are up to 15 security controls that help defenders accurately identify and prioritise information security risks. Due to the lack of clarity into the effectiveness and capabilities of these defences, and poor visibility to overall risk posture has led to a crisis of prioritisation. Lately, organisations rely on scenario based red teaming exercises which test the contribution of a security control to the security preparedness of the organisation, and testing the resilience of a control. However, these assessments don't quantify the effect of controls on the security policies already in place. Measuring this effect can help stakeholders to re-calibrate and effectively prioritise their risks. In this work, we propose a causal inference based approach to understand the influence of security control on patching behaviour in the organisations. We introduce a novel scoring function for security controls based on 6 criteria to evaluate its effectiveness. Utilising the scoring function and state of art causal inference methods we estimate the average effect (in days) of a control in patching policy of an organisation. We also assess the influence of individual control for CVE's which have high vs low CVSS scores. We validate the proposed method on observational data collected from 2000 organisations with varied asset sizes. We estimate that on an average there is a delay of 9.5 days in the patching of a CVE due to the presence of security controls on an asset. We also analyse the assumptions and algorithms with refuting methods to validate the predicted estimates and generalisation of the observed outcomes.
引用
收藏
页码:556 / 566
页数:11
相关论文
共 50 条
  • [21] Causal effect estimation and inference using Stata
    Terza, Joseph V.
    STATA JOURNAL, 2017, 17 (04) : 939 - 961
  • [22] Model-based inference on average causal effect in observational clustered data
    Meng Wu
    Recai M. Yucel
    Health Services and Outcomes Research Methodology, 2019, 19 : 36 - 60
  • [23] Population metrics for suicide events: A causal inference approach
    He, Hua
    Lu, Naiji
    Stephens, Brady
    Xia, Yinglin
    Bossarte, Robert M.
    Kane, Cathleen P.
    Tang, Wan
    Tu, Xin M.
    STATISTICAL METHODS IN MEDICAL RESEARCH, 2019, 28 (02) : 503 - 514
  • [24] Assessing a surrogate predictive value: a causal inference approach
    Alonso, Ariel
    Van der Elst, Wim
    Meyvisch, Paul
    STATISTICS IN MEDICINE, 2017, 36 (07) : 1083 - 1098
  • [25] Offline Feature-Based Pricing Under Censored Demand: A Causal Inference Approach
    Tang, Jingwen
    Qi, Zhengling
    Fang, Ethan
    Shi, Cong
    M&SOM-MANUFACTURING & SERVICE OPERATIONS MANAGEMENT, 2025, : 535 - 553
  • [26] A distributional approach for causal inference using propensity scores
    Tan, Zhiqiang
    JOURNAL OF THE AMERICAN STATISTICAL ASSOCIATION, 2006, 101 (476) : 1619 - 1637
  • [27] Validating predictors of therapeutic success: A causal inference approach
    Abad, Ariel Alonso
    Van der Elst, Wim
    Molenberghs, Geert
    STATISTICAL MODELLING, 2015, 15 (06) : 619 - 636
  • [28] Harmonization with Flow-Based Causal Inference
    Wang, Rongguang
    Chaudhari, Pratik
    Davatzikos, Christos
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION - MICCAI 2021, PT III, 2021, 12903 : 181 - 190
  • [29] Causal Inference for Knowledge Graph Based Recommendation
    Wei, Yinwei
    Wang, Xiang
    Nie, Liqiang
    Li, Shaoyu
    Wang, Dingxian
    Chua, Tat-Seng
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (11) : 11153 - 11164
  • [30] Evolving Medical Ontologies based on Causal Inference
    Hu, Hengyi
    Kerschberg, Larry
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM), 2018, : 954 - 957