Feature models to boost the vulnerability management process?

被引:1
|
作者
Jesus Varela-Vaca, Angel [1 ]
Borrego, Diana [1 ]
Teresa Gomez-Lopez, Maria [1 ]
Gasca, Rafael M. [1 ]
German Marquez, A. [1 ]
机构
[1] Univ Seville, Data Centr Comp Res Hub IDEA, Av Reina Mercedes, Seville 41012, Spain
关键词
Cybersecurity; Feature model; Vulnerability; Exploits; Reasoning; Vulnerable management process; SECURITY;
D O I
10.1016/j.jss.2022.111541
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Vulnerability management is a critical and very challenging process that allows organisations to design a procedure to identify potential vulnerabilities, assess the level of risk, and define remediation mechanisms to address threats. Thus, the large number of configuration options in systems makes it extremely difficult to identify which configurations are affected by vulnerabilities and even assess how systems may be affected. There are several repositories to store information on systems, software vul-nerabilities, and exploits. However, they are largely scattered, offer different formats and information, and their use has limitations, complicating vulnerability management automation. For this reason, we introduce a discussion concerning modelling in vulnerability management and the proposal of feature models as a means to collect the variability of software and system configurations to facilitate the vulnerability management process. This paper presents AMADEUS-Exploit, a feature model -based solution that provides query and reasoning mechanisms that make it easier for vulnerability management experts. The power of AMADEUS-Exploit is shown and evaluated in three different ways: first, the solution is compared with other vulnerability management tools; second, the solution is faced with another in a complex scenario with 4,000 vulnerabilities and 700 exploits; and finally, our solution was used in a real project demonstrating the usability of reasoning operations to determine potential vulnerabilities. (c) 2022 Elsevier Inc. All rights reserved.
引用
收藏
页数:22
相关论文
共 50 条
  • [1] Vulnerability Management Models Using a Common Vulnerability Scoring System
    Walkowski, Michal
    Oko, Jacek
    Sujecki, Slawomir
    [J]. APPLIED SCIENCES-BASEL, 2021, 11 (18):
  • [2] Efficient Vulnerability Management Process in the Military
    Baek, Seungjin
    Kim, Young-Gab
    [J]. 2019 INTERNATIONAL CONFERENCE ON PLATFORM TECHNOLOGY AND SERVICE (PLATCON), 2019, : 149 - 153
  • [3] Variability management with feature models
    Beuche, D
    Papajewski, H
    Schröder-Preikschat, W
    [J]. SCIENCE OF COMPUTER PROGRAMMING, 2004, 53 (03) : 333 - 352
  • [4] Siemens buys IndX to boost process management
    不详
    [J]. CONTROL ENGINEERING, 2004, 51 (01) : 22 - 22
  • [5] Improving Vulnerability Management Through Process Mining
    Meyer, Christina
    Heininger, Richard
    Stary, Christian
    [J]. Applied Sciences (Switzerland), 2024, 14 (23):
  • [6] Variability Management beyond Feature Models
    Lamprecht, Anna-Lena
    Naujokat, Stefan
    Schaefer, Ina
    [J]. COMPUTER, 2013, 46 (11) : 48 - 54
  • [7] Extending Feature Models to Express Variability in Business Process Models
    Cognini, Riccardo
    Corradini, Flavio
    Polini, Andrea
    Re, Barbara
    [J]. ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS, CAISE 2015, 2015, 215 : 245 - 256
  • [8] Improving an emergency repair process with feature models
    Ignaim, Karam
    Fernandes, Joao M.
    [J]. JOURNAL OF SOFTWARE-EVOLUTION AND PROCESS, 2024,
  • [9] Process management - Models and methods
    Burchert, H
    [J]. BETRIEBSWIRTSCHAFTLICHE FORSCHUNG UND PRAXIS, 1999, 51 (02): : 238 - 239
  • [10] Improving Incident Management Processes with Feature Models
    Ignaim, Karam Mustafa
    Fernandes, João M.
    [J]. Journal of Cyber Security and Mobility, 2024, 13 (04): : 701 - 724