A vulnerability prioritization system using a fuzzy risk analysis approach

被引:0
|
作者
Dondo, Maxwell G. [1 ]
机构
[1] Def Res & Dev Canada Ottawa, Ottawa, ON, Canada
关键词
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this work, we present a fuzzy systems approach for assessing the relative potential risk associated with computer network assets exposed to attack by vulnerabilities. We use this approach to rank vulnerabilities so that analysts can prioritize their work based on the potential risk exposure of assets and networks. We associate vulnerabilities with individual assets, and therefore networks, and develop fuzzy models of the vulnerability attributes. Fuzzy rules are then used to make ail inference on the risk exposure and the likelihood of attack, which allows us to rank the vulnerabilities and show which ones need more immediate attention. We argue that our approach has more meaningful vulnerability prioritization values than the severity level calculated by the popular Common Vulnerability Scoring System (CVSS) approach.
引用
收藏
页码:525 / 539
页数:15
相关论文
共 50 条
  • [1] Risk prioritization in a gas power plant using Fuzzy inference system
    Agarwal, Mohit
    Narayanan, Aditya G.
    Shreyansh
    Srivastava, Priyank
    [J]. PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE CONFLUENCE 2018 ON CLOUD COMPUTING, DATA SCIENCE AND ENGINEERING, 2018, : 753 - 757
  • [2] Risk-based test case prioritization using a fuzzy expert system
    Hettiarachchi, Charitha
    Do, Hyunsook
    Choi, Byoungju
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2016, 69 : 1 - 15
  • [3] RISK MEASUREMENT AND PRIORITIZATION USING FUZZY FMEA APPROACH - A STUDY OF PROCESS IN AUTOMOTIVE INDUSTRY
    Grecu, Iuliana
    Belu, Nadia
    Rachieru, Nicoleta
    [J]. MANAGEMENT PERSPECTIVES IN THE DIGITAL TRANSFORMATION, 2019, : 325 - 335
  • [4] Risk Prioritization and Management in Gas Stations by using Fuzzy AHP and IPA Analysis
    Mohsin, Muhammad
    Wang Zhan-ao
    Zhang Shijun
    Huang Weilun
    Yin Hengbin
    [J]. JOURNAL OF SCIENTIFIC & INDUSTRIAL RESEARCH, 2021, 80 (12): : 1107 - 1116
  • [5] A comparative analysis of Fuzzy AHP and Fuzzy VIKOR methods for prioritization of the risk criteria of an autonomous vehicle system
    Mehrparvar, Marmar
    Majak, Jueri
    Karjust, Kristo
    [J]. PROCEEDINGS OF THE ESTONIAN ACADEMY OF SCIENCES, 2024, 73 (02) : 116 - 123
  • [6] Software vulnerability prioritization using vulnerability description
    Ruchi Sharma
    Ritu Sibal
    Sangeeta Sabharwal
    [J]. International Journal of System Assurance Engineering and Management, 2021, 12 : 58 - 64
  • [7] Software vulnerability prioritization using vulnerability description
    Sharma, Ruchi
    Sibal, Ritu
    Sabharwal, Sangeeta
    [J]. INTERNATIONAL JOURNAL OF SYSTEM ASSURANCE ENGINEERING AND MANAGEMENT, 2021, 12 (01) : 58 - 64
  • [8] Enterprise risk management in supply chain operation: a fuzzy risk prioritization approach
    Mukherjee, Swarup
    De, Anupam
    Roy, Supriyo
    [J]. BENCHMARKING-AN INTERNATIONAL JOURNAL, 2024,
  • [9] Risk Evaluation and Prioritization in Bridge Construction Projects Using System Dynamics Approach
    Mortazavi, Seyedmehdi
    Kheyroddin, Ali
    Naderpour, Hosein
    [J]. PRACTICE PERIODICAL ON STRUCTURAL DESIGN AND CONSTRUCTION, 2020, 25 (03)
  • [10] Use Case Prioritization using Fuzzy Logic System
    Ahmed, Rashad
    Musleh, Dhiaa
    Ahmed, Moataz
    El-Attar, Mohamed
    [J]. 2014 5TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2014, : 149 - 152