EVMAT: An OVAL and NVD Based Enterprise Vulnerability Modeling and Assessment Tool

被引:0
|
作者
Wu, Bin [1 ]
Wang, Andy Ju An [1 ]
机构
[1] Southern Polytech State Univ, Marietta, GA 30060 USA
基金
美国国家科学基金会;
关键词
EVMAT; Enterprise vulnerability; Modeling; Assessment;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Enterprise-wide vulnerability assessment is one of the key processes of Enterprise Risk Management. However, due to the complexity of IT systems, it requires extremely time-consuming effort for information security professionals to evaluate enterprise vulnerability scores and security status on a regular basis. Security administrators are seeking for an automated tool that helps monitor and evaluate the overall vulnerability of an enterprise. This paper presents a novel tool, EVMAT, which provides a dashboard solution for monitoring enterprise vulnerability levels for properly enterprise risk management. It firstly models the enterprise vulnerability topology and then gathers relevant information automatically and remotely from different constituents and resources existed in enterprise network. Next it computes and analyzes the vulnerability situation of the enterprise according to a carefully-designed metrics. Experiments on a small E-commerce company demonstrate the great potentials of our tool for enterprise-level security.
引用
收藏
页码:115 / 120
页数:6
相关论文
共 50 条
  • [1] A vulnerability assessment tool based on OVAL in linux system
    Kwon, Y
    Lee, HJ
    Lee, G
    [J]. NETWORK AND PARALLEL COMPUTING, PROCEEDINGS, 2004, 3222 : 653 - 660
  • [2] Intelligent tool for enterprise vulnerability assessment on a distributed network environment using Nessus and OVAL
    Kim, Y
    Baek, SY
    Lee, G
    [J]. KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 2, PROCEEDINGS, 2005, 3682 : 1056 - 1061
  • [3] A Vulnerability Assessment Tool Based on OVAL in System Block Model
    Lee, Geuk
    Ko, Il-Seok
    Kim, Tai-hoon
    [J]. INTELLIGENT COMPUTING, PART I: INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING, ICIC 2006, PART I, 2006, 4113 : 1115 - 1120
  • [4] An OVAL-based active vulnerability assessment system for enterprise computer networks
    Chen, Xiuzhen
    Zheng, Qinghua
    Guan, Xiaohong
    [J]. INFORMATION SYSTEMS FRONTIERS, 2008, 10 (05) : 573 - 588
  • [5] An OVAL-based active vulnerability assessment system for enterprise computer networks
    Xiuzhen Chen
    Qinghua Zheng
    Xiaohong Guan
    [J]. Information Systems Frontiers, 2008, 10 : 573 - 588
  • [6] Network Simulation and Vulnerability Assessment Tool for an Enterprise Network
    Dhivvya, J. P.
    Muralidharan, Divya
    Raj, Neha
    Kumar, Barnala Kiran
    [J]. 2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [7] Ovaldroid: an OVAL-based Vulnerability Assessment Framework for Android
    Barrere, Martin
    Hurel, Gaetan
    Badonnel, Remi
    Festor, Olivier
    [J]. 2013 IFIP/IEEE INTERNATIONAL SYMPOSIUM ON INTEGRATED NETWORK MANAGEMENT (IM 2013), 2013, : 1074 - 1075
  • [8] Development of oval based vulnerability management tool (OVMT) on a distributed network environment
    Lee, Geuk
    Kim, Youngsup
    Youk, Sang Jo
    [J]. KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 3, PROCEEDINGS, 2006, 4253 : 1042 - 1049
  • [9] The Cyber Security Modeling Language: A Tool for Assessing the Vulnerability of Enterprise System Architectures
    Sommestad, Teodor
    Ekstedt, Mathias
    Holm, Hannes
    [J]. IEEE SYSTEMS JOURNAL, 2013, 7 (03): : 363 - 373
  • [10] Design and Implementation of a MOF based Enterprise Modeling Tool
    Li Jin
    Zhan Dechen
    Nie Lanshun
    Xu Xiaofei
    [J]. I-ESA 2009: INTERNATIONAL CONFERENCE ON INTEROPERABILITY FOR ENTERPRISE SOFTWARE AND APPLICATIONS CHINA, PROCEEDINGS, 2009, : 76 - 81