An Experimental Approach to Network Monitoring Using Quantitative Security Metrics

被引:0
|
作者
El-Hassan, Fadi [1 ]
Matrawy, Ashraf [1 ]
Seddigh, Nabil [2 ]
Nandy, Biswajit [2 ]
机构
[1] Carleton Univ, Dept Syst & Comp Engn, Elect Engn, Ottawa, ON, Canada
[2] Solana Networks, Ottawa, ON, Canada
来源
基金
加拿大自然科学与工程研究理事会;
关键词
Network Security; Information Assurance; Quantitative Security Metrics; Intrusion Detection;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper presents our work in developing quantitative metrics for network security evaluation and monitoring. We introduce a unified security health index that indicates the security status of the network. Recent efforts have focused on a framework of security metrics derived from a variety of technical, organizational, and operational sources. However, network administrators have faced challenges in deploying these frameworks in operational networks. The challenges stem from the sheer volume of metrics and the difficulty of combining them into a unified security health index. Regardless, the time has come for security metrics to make the bridge from the theoretical to the practical. In this paper, our contribution is threefold. First, we conduct practical experiments of fusing security alerts extracted from the logs of the Snort Intrusion Detection System. The experiments are conducted against real network traces. Second, we classify Snort security alerts into well-defined metric groups. Our final contribution is to study the fusing of metric groups into a single overall metric using simple combination criterion. This metric represents the security status of a network. The results of this experimental work demonstrate that operational deployment of a security network health index framework is viable and can produce meaningful results if combined with existing security tools such as IDSs.
引用
收藏
页码:48 / 62
页数:15
相关论文
共 50 条
  • [21] On the Computation of Centrality Metrics for Network Security in Mesh Networks
    Maccari, Leonardo
    Quynh Nguyen
    Lo Cigno, Renato
    [J]. 2016 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2016,
  • [22] Network Security Metrics and Performance for Healthcare Systems Management
    Liu, Vicky
    Tesfamicael, Aklilu Daniel
    Caelli, William
    Sahama, Tony
    [J]. 2015 17TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATION & SERVICES (HEALTHCOM), 2015, : 189 - 194
  • [23] Quantitative Security Assurance Metrics - REST API Case Studies
    Katt, Basel
    Prasher, Nishu
    [J]. ECSA 2018: PROCEEDINGS OF THE 12TH EUROPEAN CONFERENCE ON SOFTWARE ARCHITECTURE: COMPANION PROCEEDINGS, 2018,
  • [24] Uncertainty of Information Applied to Network Monitoring Metrics
    Raglin, Adrienne
    Newcomb, Allison
    Scott, Lisa
    [J]. ARTIFICIAL INTELLIGENCE IN HCI, PT I, AI-HCI 2024, 2024, 14734 : 403 - 410
  • [25] CloudWatcher: Network Security Monitoring Using OpenFlow in Dynamic Cloud Networks (or: How to Provide Security Monitoring as a Service in Clouds?)
    Shin, Seungwon
    Gu, Guofei
    [J]. 2012 20TH IEEE INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2012,
  • [26] A machine learning based approach for 5G network security monitoring
    Chen, Bin
    [J]. Applied Mathematics and Nonlinear Sciences, 2024, 9 (01)
  • [27] Using Security Logs for Collecting and Reporting Technical Security Metrics
    Vaarandi, Risto
    Pihelgas, Mauno
    [J]. 2014 IEEE MILITARY COMMUNICATIONS CONFERENCE: AFFORDABLE MISSION SUCCESS: MEETING THE CHALLENGE (MILCOM 2014), 2014, : 294 - 299
  • [28] A quantitative evaluation model for network security
    Man, Dapeng
    Yang, Wu
    Yang, Yongtian
    Wang, Wei
    Zhang, Lejun
    [J]. CIS: 2007 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PROCEEDINGS, 2007, : 773 - 777
  • [29] Quantitative Network Monitoring with NetQRE
    Yuan, Yifei
    Lin, Dong
    Mishra, Ankit
    Marwaha, Sajal
    Alur, Rajeev
    Loo, Boon Thau
    [J]. SIGCOMM '17: PROCEEDINGS OF THE 2017 CONFERENCE OF THE ACM SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2017, : 99 - 112
  • [30] Quantitative research assessment: using metrics against gamed metrics
    John P. A. Ioannidis
    Zacharias Maniadis
    [J]. Internal and Emergency Medicine, 2024, 19 : 39 - 47