A hybrid ranking approach to estimate vulnerability for dynamic attacks

被引:12
|
作者
Zhao, Feng [1 ,2 ,3 ]
Huang, Heqing [1 ]
Jin, Hai [1 ,2 ,3 ]
Zhang, Qin [1 ,2 ,3 ]
机构
[1] Huazhong Univ Sci & Technol, Sch Comp Sci & Technol, Wuhan 430074, Peoples R China
[2] Serv Comp Technol & Syst Lab, Wuhan 430074, Peoples R China
[3] Cluster & Grid Comp Lab, Wuhan 430074, Peoples R China
基金
中国国家自然科学基金;
关键词
Security evaluation; Hybrid ranking; Attack graph; CVSS; Dynamic scenarios; SECURITY;
D O I
10.1016/j.camwa.2011.09.031
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
To enhance security in dynamic networks, it is important to evaluate the vulnerabilities and offer economic and practical patching strategy since vulnerability is the major driving force for attacks. In this paper, a hybrid ranking approach is presented to estimate vulnerabilities under the dynamic scenarios, which is a combination of low-level rating for vulnerability instances and high-level evaluation for the security level of the network system. Moreover, a novel quantitative model, an adapted attack graph, is also proposed to escaping isolated scoring, which takes the dynamic and logic relations among exploits into account, and significantly benefits to vulnerability analysis. To validate applicability and performance of our approach, a hybrid ranking case is implemented as experimental platform. The ranking results show that our approach differentiates the influential levels among vulnerabilities under dynamic attacking scenarios and economically enhances the security of network system. (C) 2011 Elsevier Ltd, All rights reserved.
引用
收藏
页码:4308 / 4321
页数:14
相关论文
共 50 条
  • [21] Latin hypercube approach to estimate uncertainty in ground water vulnerability
    Gurdak, Jason J.
    McCray, John E.
    Thyne, Geoffrey
    Qi, Sharon L.
    GROUND WATER, 2007, 45 (03) : 348 - 361
  • [22] Hybrid Security Classification Approach to Attacks in WiMAX
    Ahmadzadegan, M. Hossein
    Elmusrati, M.
    2013 IEEE INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING, COMPUTING AND CONTROL (ISPCC), 2013,
  • [23] Ranking schemes in hybrid Boolean systems: A new approach
    Savoy, J
    JOURNAL OF THE AMERICAN SOCIETY FOR INFORMATION SCIENCE, 1997, 48 (03): : 235 - 253
  • [24] An Efficient Page Ranking Approach Based On Hybrid Model
    Rodrigues, Lissa
    Jaswal, Shree
    2015 SECOND INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING AND COMMUNICATION ENGINEERING ICACCE 2015, 2015, : 693 - 696
  • [25] A hybrid approach to feature ranking for microarray data classification
    Popovic, Dusan
    Sifrim, Alejandro
    Moschopoulos, Charalampos
    Moreau, Yves
    De Moor, Bart
    Communications in Computer and Information Science, 2013, 384 : 241 - 248
  • [26] A Hybrid Approach to Feature Ranking for Microarray Data Classification
    Popovic, Dusan
    Sifrim, Alejandro
    Moschopoulos, Charalampos
    Moreau, Yves
    De Moor, Bart
    ENGINEERING APPLICATIONS OF NEURAL NETWORKS, PT II, 2013, 384 : 241 - 248
  • [28] Model-based hybrid dynamic event-triggered control for systems subject to DoS attacks: A hybrid system approach
    Zhao, Can
    Liu, Fucai
    Chen, Tianming
    Wang, Cancan
    INFORMATION SCIENCES, 2022, 613 : 268 - 287
  • [29] Vulnerability Assessment of Power Grids Against Cost-Constrained Hybrid Attacks
    Gao, Xiaolin
    Pu, Cunlai
    Li, Lunbo
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS II-EXPRESS BRIEFS, 2021, 68 (04) : 1477 - 1481
  • [30] Dynamic Event-Triggered Consensus for Multiagent Systems Under DoS Attacks: A Hybrid System Approach
    Liu, Guopin
    Park, Ju H.
    Hua, Changchun
    Li, Yafeng
    IEEE TRANSACTIONS ON SYSTEMS MAN CYBERNETICS-SYSTEMS, 2023, 53 (11): : 7223 - 7233