CVSS-based Multi-Factor Dynamic RiskAssessment Model for Network System

被引:0
|
作者
Wang, Tingting
Lv, Qiujian
Hu, Bo [1 ]
Sun, Degang
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100093, Peoples R China
关键词
dynamic risk assessment; Bayesian attack graphs; CVSS; attacker capability; network security; SECURITY RISK;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The risk assessment model of network systems is designed to provide quantifiable evidence to assist security administrators in choosing appropriate defend methods. Most models measure the overall risk by combining CVSS base scores of system vulnerabilities. However, they merely consider the impact of dynamic risk factors including attacker capability and evolutions of vulnerabilities. To address this issue, we propose a CVSS based Multi-Factor dynamic risk assessment Model, CMFM. It uses attack paths to model an attacker's capability, which is thus used to estimate the successful probabilities about vulnerability exploitations. Besides, we exploit both static and time-variant factors of vulnerabilities to produce a better estimation result. The final system risk assessment can then be accessed via a Bayesian attack graph. We evaluate the proposed model in two scenarios, all of which demonstrate that CMFM outperforms the state-of-the-art models in assessing the dynamic risk status of network systems.
引用
收藏
页码:289 / 294
页数:6
相关论文
共 50 条
  • [1] A revised CVSS-based system to improve the dispersion of vulnerability risk scores
    Chensi Wu
    Tao Wen
    Yuqing Zhang
    [J]. Science China Information Sciences, 2019, 62
  • [2] A revised CVSS-based system to improve the dispersion of vulnerability risk scores
    Wu, Chensi
    Wen, Tao
    Zhang, Yuqing
    [J]. SCIENCE CHINA-INFORMATION SCIENCES, 2019, 62 (03)
  • [3] revised CVSS-based system to improve the dispersion of vulnerability risk scores
    Chensi WU
    Tao WEN
    Yuqing ZHANG
    [J]. Science China(Information Sciences), 2019, 62 (03) : 193 - 195
  • [4] The Research of a Multi-Factor Dynamic Authorization Model
    Liu, Jing
    Liu, Chao
    Jiao, Dongliang
    Chen, Jiaopeng
    [J]. 2012 NINTH IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING (ICEBE), 2012, : 201 - 205
  • [5] DYNAMIC MODEL OF MULTI-PRODUCT, MULTI-FACTOR FIRM
    GRAHAM, DA
    NAYLOR, TH
    [J]. WESTERN ECONOMIC JOURNAL, 1972, 10 (01): : 33 - 44
  • [6] Dynamic model of nonlinear multi-factor high speed bearing rotor system
    Hao, Lina
    Deng, Song
    Qian, Dongsheng
    Hua, Lin
    [J]. Zhongnan Daxue Xuebao (Ziran Kexue Ban)/Journal of Central South University (Science and Technology), 2021, 52 (02): : 400 - 409
  • [7] A multi-factor model of heterogeneous traders in a dynamic stock market
    Pyo, Dong-Jin
    [J]. COGENT ECONOMICS & FINANCE, 2018, 5 (01):
  • [8] Dynamic Multi-factor Authentication for Smartphone
    Yohan, Alexander
    Lo, Nai-Wei
    Lie, Henry Roes
    [J]. 2016 IEEE 27TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR, AND MOBILE RADIO COMMUNICATIONS (PIMRC), 2016, : 2448 - 2453
  • [9] A PATTERN-BASED MULTI-FACTOR AUTHENTICATION SYSTEM
    Pankhuri
    Sinha, Akash
    Shrivastava, Gulshan
    Kumar, Prabhat
    [J]. SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2019, 20 (01): : 101 - 112
  • [10] CCTV-Based Multi-Factor Authentication System
    Kwon, Byoung-Wook
    Sharma, Pradip Kumar
    Park, Jong-Hyuk
    [J]. JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2019, 15 (04): : 904 - 919