An Experimental Approach to Network Monitoring Using Quantitative Security Metrics

被引:0
|
作者
El-Hassan, Fadi [1 ]
Matrawy, Ashraf [1 ]
Seddigh, Nabil [2 ]
Nandy, Biswajit [2 ]
机构
[1] Carleton Univ, Dept Syst & Comp Engn, Elect Engn, Ottawa, ON, Canada
[2] Solana Networks, Ottawa, ON, Canada
来源
基金
加拿大自然科学与工程研究理事会;
关键词
Network Security; Information Assurance; Quantitative Security Metrics; Intrusion Detection;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents our work in developing quantitative metrics for network security evaluation and monitoring. We introduce a unified security health index that indicates the security status of the network. Recent efforts have focused on a framework of security metrics derived from a variety of technical, organizational, and operational sources. However, network administrators have faced challenges in deploying these frameworks in operational networks. The challenges stem from the sheer volume of metrics and the difficulty of combining them into a unified security health index. Regardless, the time has come for security metrics to make the bridge from the theoretical to the practical. In this paper, our contribution is threefold. First, we conduct practical experiments of fusing security alerts extracted from the logs of the Snort Intrusion Detection System. The experiments are conducted against real network traces. Second, we classify Snort security alerts into well-defined metric groups. Our final contribution is to study the fusing of metric groups into a single overall metric using simple combination criterion. This metric represents the security status of a network. The results of this experimental work demonstrate that operational deployment of a security network health index framework is viable and can produce meaningful results if combined with existing security tools such as IDSs.
引用
收藏
页码:48 / 62
页数:15
相关论文
共 50 条
  • [1] Model-Based Quantitative Network Security Metrics: A Survey
    Ramos, Alex
    Lazar, Marcella
    Holanda Filho, Raimir
    Rodrigues, Joel J. P. C.
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2017, 19 (04): : 2704 - 2734
  • [2] A novel quantitative approach for measuring network security
    Ahmed, Mohammad Salim
    Al-Shaer, Ehab
    Khan, Latifur
    [J]. 27TH IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (INFOCOM), VOLS 1-5, 2008, : 76 - 80
  • [3] Survey on network system security metrics
    Wu, Chensi
    Xie, Weiqiang
    Ji, Yixiao
    Yang, Su
    Jia, Ziyi
    Zhao, Song
    Zhang, Yuqing
    [J]. Tongxin Xuebao/Journal on Communications, 2019, 40 (06): : 14 - 31
  • [4] Evaluation of Network Risk Using Attack Graph Based Security Metrics
    Kumar, Santosh
    Negi, Anuradha
    Prasad, Keshav
    Mahanti, Aniket
    [J]. 2016 IEEE 14TH INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, 14TH INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, 2ND INTL CONF ON BIG DATA INTELLIGENCE AND COMPUTING AND CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/DATACOM/CYBERSC, 2016, : 91 - 93
  • [5] Application of Quantitative Security Metrics in Cloud Computing
    Torkura, Kennedy A.
    Cheng, Feng
    Meinel, Christoph
    [J]. 2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 256 - 262
  • [6] A Big Data and machine learning approach for network monitoring and security
    Maccari, Leonardo
    Passerini, Andrea
    [J]. SECURITY AND PRIVACY, 2019, 2 (01):
  • [7] A Formal Approach to Information Security Metrics
    Chakraborty, Agniswar
    Sengupta, Anirban
    Mazumdar, Chandan
    [J]. 2012 THIRD INTERNATIONAL CONFERENCE ON EMERGING APPLICATIONS OF INFORMATION TECHNOLOGY (EAIT), 2012, : 439 - 442
  • [8] Automatic Security Analysis Using Security Metrics
    Sun, Kun
    Jajodia, Sushil
    Li, Jason
    Cheng, Yi
    Tang, Wei
    Singhal, Anoop
    [J]. 2011 - MILCOM 2011 MILITARY COMMUNICATIONS CONFERENCE, 2011, : 1207 - 1212
  • [9] Using security patterns to combine security metrics
    Heyman, Thomas
    Scandariato, Riccardo
    Huygens, Christophe
    Joosen, Wouter
    [J]. ARES 2008: PROCEEDINGS OF THE THIRD INTERNATIONAL CONFERENCE ON AVAILABILITY, SECURITY AND RELIABILITY, 2008, : 1156 - 1163
  • [10] Network Security Metrics: Vital Ingredients for Measuring Networks Security
    Bindra, Naveen
    Sood, Manu
    [J]. 2018 FIFTH INTERNATIONAL CONFERENCE ON PARALLEL, DISTRIBUTED AND GRID COMPUTING (IEEE PDGC), 2018, : 221 - 226