A MULTI-LAYER TREE MODEL FOR ENTERPRISE VULNERABILITY MANAGEMENT

被引:0
|
作者
Wu, Bin [1 ]
Wang, Andy Ju An [1 ]
机构
[1] Southern Polytech State Univ, Marietta, GA 30060 USA
基金
美国国家科学基金会;
关键词
Enterprise vulnerability; Multi-level tree model; Assessment; EVMAT; NVD;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conducting enterprise-wide vulnerability assessment (VA) on a regular basis plays an important role in assessing an enterprise's information system security status. However, an enterprise network is always very complex, separated into different types of zones, and consisting hundreds of hosts in the networks. The complexity of IT system makes VA an extremely time-consuming task for security professionals. They are seeking for an automated tool that helps monitor and manage the overall vulnerability of an enterprise. This paper presents a novel methodology that provides a dashboard solution for managing enterprise level vulnerability. In our methodology, we develop a multi-layer tree based model to describe enterprise vulnerability topology. Then we apply a client/server structure to gather vulnerability information from enterprise resources automatically. Finally a set of well-defined metric formulas is applied to produce a normalized vulnerability score for the whole enterprise. We also developed the implementation of our methodology, EVMAT, and Enterprise Vulnerability Management and Assessment Tool, to test our method. Experiments on a small E-commerce company and a small IT company demonstrate the great potentials of our tool for enterprise-level security.
引用
收藏
页码:389 / 394
页数:6
相关论文
共 50 条
  • [21] Structural Vulnerability Analysis for Large-Scale Distributed System based on Multi-layer Topology Model
    Kuang, Xiaohui
    Zhao, Gang
    Tang, Yong
    Li, Jin
    PRZEGLAD ELEKTROTECHNICZNY, 2012, 88 (3B): : 78 - 83
  • [22] Applying the Stackelberg game to assess critical infrastructure vulnerability: Based on a general multi-layer network model
    Li, Haitao
    Ji, Lixin
    Wang, Kai
    Liu, Shuo
    Liu, Shuxin
    CHAOS, 2024, 34 (12)
  • [23] Augmenting SDN by a Multi-Layer Network Model
    Farkas, Balazs
    Zsoka, Zoltan
    2016 EUROPEAN CONFERENCE ON NETWORKS AND COMMUNICATIONS (EUCNC), 2016, : 215 - 219
  • [24] A theoretical model for multi-layer jamming systems
    Caruso, Fabio
    Mantriota, Giacomo
    Afferrante, Luciano
    Reina, Giulio
    Mechanism and Machine Theory, 2022, 172
  • [25] A Multi-layer Model for Website Defacement Detection
    Xuan Dau Hoang
    Ngoc Tuong Nguyen
    SOICT 2019: PROCEEDINGS OF THE TENTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY, 2019, : 508 - 513
  • [26] A Multi-layer Security Model for Internet of Things
    Yang, Xue
    Li, Zhihua
    Geng, Zhenmin
    Zhang, Haitao
    INTERNET OF THINGS-BK, 2012, 312 : 388 - 393
  • [27] Multi-Layer Cournot-Congestion Model
    Willis, T.
    Punzo, G.
    IFAC PAPERSONLINE, 2022, 55 (40): : 61 - 66
  • [28] A theoretical model for multi-layer jamming systems
    Caruso, Fabio
    Mantriota, Giacomo
    Afferrante, Luciano
    Reina, Giulio
    MECHANISM AND MACHINE THEORY, 2022, 172
  • [29] Multi-layer model of correlated energy prices
    Grine, Slimane
    Diko, Pavel
    JOURNAL OF COMPUTATIONAL AND APPLIED MATHEMATICS, 2010, 233 (10) : 2590 - 2610
  • [30] A Multi-layer GSM Network Design Model
    de Aguiar, Alexei Barbosa
    Pinheiro, Placido Rogerio
    Neto, Alvaro de Menezes S.
    Pinheiro, Rebecca F.
    Cunha, Ruddy P. P.
    NOVEL ALGORITHMS AND TECHNIQUES IN TELECOMMUNICATIONS AND NETWORKING, 2010, : 457 - 460