A MULTI-LAYER TREE MODEL FOR ENTERPRISE VULNERABILITY MANAGEMENT

被引:0
|
作者
Wu, Bin [1 ]
Wang, Andy Ju An [1 ]
机构
[1] Southern Polytech State Univ, Marietta, GA 30060 USA
基金
美国国家科学基金会;
关键词
Enterprise vulnerability; Multi-level tree model; Assessment; EVMAT; NVD;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Conducting enterprise-wide vulnerability assessment (VA) on a regular basis plays an important role in assessing an enterprise's information system security status. However, an enterprise network is always very complex, separated into different types of zones, and consisting hundreds of hosts in the networks. The complexity of IT system makes VA an extremely time-consuming task for security professionals. They are seeking for an automated tool that helps monitor and manage the overall vulnerability of an enterprise. This paper presents a novel methodology that provides a dashboard solution for managing enterprise level vulnerability. In our methodology, we develop a multi-layer tree based model to describe enterprise vulnerability topology. Then we apply a client/server structure to gather vulnerability information from enterprise resources automatically. Finally a set of well-defined metric formulas is applied to produce a normalized vulnerability score for the whole enterprise. We also developed the implementation of our methodology, EVMAT, and Enterprise Vulnerability Management and Assessment Tool, to test our method. Experiments on a small E-commerce company and a small IT company demonstrate the great potentials of our tool for enterprise-level security.
引用
收藏
页码:389 / 394
页数:6
相关论文
共 50 条
  • [31] Boundary layer considerations in a multi-layer model for LDL accumulation
    Iasiello, Marcello
    Vafai, Kambiz
    Andreozzi, Assunta
    Bianco, Nicola
    COMPUTER METHODS IN BIOMECHANICS AND BIOMEDICAL ENGINEERING, 2018, 21 (15) : 803 - 811
  • [32] Multi-layer optimization for QKD and key management networks
    Wenning, Mario
    Samonaki, Maria
    Patri, Sai Kireet
    Fehenberger, Tobias
    Mas-Machuca, Carmen
    JOURNAL OF OPTICAL COMMUNICATIONS AND NETWORKING, 2023, 15 (11) : 938 - 947
  • [33] A multi-layer control scheme for microgrid energy management
    Cominesi, S. Raimondi
    La Bella, A.
    Farina, M.
    Scattolini, R.
    IFAC PAPERSONLINE, 2016, 49 (27): : 256 - 261
  • [34] Malicious documents detection for business process management based on multi-layer abstract model
    Yu, Min
    Jiang, Jianguo
    Li, Gang
    Lou, Chenzhe
    Liu, Yunzheng
    Liu, Chao
    Huang, Weiqing
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 99 : 517 - 526
  • [35] A Multi-layer Optimal Chiller Operation Management Framework
    Ye, Yanzhu
    Sharma, Ratnesh
    Guo, Feng
    2016 52ND ANNUAL MEETING OF THE IEEE INDUSTRY APPLICATIONS SOCIETY (IAS), 2016,
  • [36] Multi-layer multicast key management with threshold cryptography
    Dexter, S
    Belostotskiy, R
    Eskicioglu, AM
    SECURITY, STEGANOGRAPHY, AND WATERMARKING OF MULTIMEDIA CONTENTS VI, 2004, 5306 : 705 - 715
  • [37] A Multi-Layer LoRaWAN Infrastructure for Smart Waste Management
    Baldo, David
    Mecocci, Alessandro
    Parrino, Stefano
    Peruzzi, Giacomo
    Pozzebon, Alessandro
    SENSORS, 2021, 21 (08)
  • [38] Timing- and Interference-Free Multi-layer Routing Tree
    Su, Pi-Hua
    Huang, Hsin-Hsiung
    Hsieh, Tsai-Ming
    2011 IEEE 54TH INTERNATIONAL MIDWEST SYMPOSIUM ON CIRCUITS AND SYSTEMS (MWSCAS), 2011,
  • [39] Layout-aware multi-layer multi-level scan tree synthesis
    Wang, Sying-Jyan
    Li, Xin-Lonlg
    Li, Katherine Shu-Min
    PROCEEDINGS OF THE 16TH ASIAN TEST SYMPOSIUM, 2007, : 129 - +
  • [40] The model for multi-layer heat shielding with inner layer of intumescent material
    Sushko, V.
    Makushina, A.
    Korablev, V.
    Sharkov, A.
    HEAT TRANSFER RESEARCH, 2008, 39 (07) : 619 - 624