A novel quantitative approach for measuring network security

被引:0
|
作者
Ahmed, Mohammad Salim [1 ]
Al-Shaer, Ehab [2 ]
Khan, Latifur [1 ]
机构
[1] Univ Texas Dallas, Dept Comp Sci, Dallas, TX 75230 USA
[2] De Paul Univ, Sch Comp Sci Telecommun & Informat Syst, Chicago, IL USA
基金
美国国家科学基金会;
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Evaluation of network security is an essential step in securing any network. This evaluation can help security professionals in making optimal decisions about how to design securing countermeasures, to choose between alternative security architectures, and to systematically modify security configurations in order to improve security. However, the security of a network depends on a number of dynamically changing factors such as emergence of new vulnerabilities and threats, policy, structure and network traffic. Identifying, quantifying and validating these factors using security metrics is a major challenge in this area. In this paper, we propose a novel security metric framework that identifies and quantities objectively the most significant security risk factors, which include existing vulnerabilities, historical trend of vulnerability of the remotely accessible services, prediction of potential vulnerabilities for any, general network service and their estimated severity and finally polio, resistance to attack propagation within the network. We then describe our rigorous validation experiments using real-life vulnerability data of the past 6 years from National Vulnerability Database (NVD) to show the high accuracy and confidence of the proposed metrics. Some previous works have considered vulnerabilities using code analysis. However, as far as we know. this is the first work to study and analyze these metrics for network security evaluation using publicly available vulnerability information and security policy configuration.
引用
收藏
页码:76 / 80
页数:5
相关论文
共 50 条
  • [41] A Novel Network Modeling and Evaluation Approach for Security Vulnerability Quantification in Substation Automation Systems
    Ko, Jongbin
    Lee, Seokjun
    Lim, Yong-hun
    Ju, Seong-ho
    Shon, Taeshik
    [J]. IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2013, E96D (09): : 2021 - 2025
  • [42] A QUANTITATIVE APPROACH TO MEASURING THE SOCIAL EFFECTS OF EPILEPSY
    CHAPLIN, JE
    YEPEZ, R
    SHORVON, S
    FLOYD, M
    [J]. NEUROEPIDEMIOLOGY, 1990, 9 (03) : 151 - 158
  • [43] A semantic network approach to measuring sentiment
    Danowski J.A.
    Yan B.
    Riopelle K.
    [J]. Quality & Quantity, 2021, 55 (1) : 221 - 255
  • [44] A network approach to measuring state preferences
    Gallop, Max
    Minhas, Shahryar
    [J]. NETWORK SCIENCE, 2021, 9 (02) : 135 - 152
  • [45] A Jackson network-based model for quantitative analysis of network security
    Xiang, ZT
    Chen, YF
    Jian, W
    Yan, F
    [J]. INTELLIGENCE AND SECURITY INFORMATICS, PROCEEDINGS, 2005, 3495 : 517 - 522
  • [46] A novel approach to measuring cell-mediated lympholysis using quantitative flow and imaging cytometry
    La Muraglia, G. M., II
    O'Neil, M. J.
    Madariaga, M. L.
    Michel, S. G.
    Mordecai, K. S.
    Allan, J. S.
    Madsen, J. C.
    Hanekamp, I. M.
    Preffer, F. I.
    [J]. JOURNAL OF IMMUNOLOGICAL METHODS, 2015, 427 : 85 - 93
  • [47] A Novel approach for Implementing Security over Vehicular Ad hoc network using Signcryption through Network Grid
    Vijayan, R.
    Singh, Sumitkumar
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2011, 2 (04) : 44 - 48
  • [48] A New Approach to Analysis the Security of Compensated Measuring PUFs
    Diez-Senorans, G.
    Garcia-Bosque, M.
    Sanchez-Azqueta, C.
    Celma, S.
    [J]. 24TH IEEE EUROPEAN CONFERENCE ON CIRCUIT THEORY AND DESIGN (ECCTD 2020), 2020,
  • [49] A robust approach for measuring the margin -coefficient- of security
    Cervera, J.
    [J]. INFORMES DE LA CONSTRUCCION, 2010, 62 (518) : 33 - 42
  • [50] The availability of food in Mexico: an approach to measuring food security
    Yadihra Cruz-Sánchez
    Alma Aguilar-Estrada
    Julio Baca-del Moral
    Alejandro Ismael Monterroso-Rivas
    [J]. Agriculture & Food Security, 13 (1):