A Novel Quantitative Approach For Measuring Network Security

A Novel Quantitative Approach For Measuring Network Security
复制标题

衡量网络安全的新颖定量方法

DOI:
--
复制
发表时间:
2008
期刊:
IEEE INFOCOM 2008 - The 27th Conference on Computer Communications
影响因子:
--
通讯作者:
L. Khan
L. Khan
中科院分区:
--
文献类型:
--
作者:
Mohammad Salim Ahmed;E. Al;L. Khan

文献摘要

被引文献

相似文献

网络安全评估是确保任何网络安全的重要步骤。这种评估可以帮助安全专业人员就如何设计安全对策、在替代安全体系结构之间进行选择以及系统地修改安全配置以提高安全性做出最佳决策。然而,网络的安全依赖于许多动态变化的因素,如新的漏洞和威胁的出现、策略结构和网络流量。使用安全指标识别、量化和验证这些因素是这一领域的主要挑战。在本文中,我们提出了一种新的安全度量框架,它客观地识别和量化最重要的安全风险因素,包括现有的漏洞、远程可访问服务的漏洞的历史趋势、对任何一般网络服务的潜在漏洞的预测及其估计的严重程度,最后是对攻击在网络中传播的策略抵抗。然后,我们描述了我们使用国家漏洞数据库(NVD)[10]过去6年的真实漏洞数据进行的严格验证实验,以显示所提出的度量的高精度和置信度。以前的一些工作使用代码分析来考虑漏洞。然而,据我们所知,这是第一次使用公开的漏洞信息和安全策略配置来研究和分析这些指标来进行网络安全评估。
Evaluation of network security is an essential step in securing any network. This evaluation can help security professionals in making optimal decisions about how to design security countermeasures, to choose between alternative security architectures, and to systematically modify security configurations in order to improve security. However, the security of a network depends on a number of dynamically changing factors such as emergence of new vulnerabilities and threats, policy structure and network traffic. Identifying, quantifying and validating these factors using security metrics is a major challenge in this area. In this paper, we propose a novel security metric framework that identifies and quantifies objectively the most significant security risk factors, which include existing vulnerabilities, historical trend of vulnerability of the remotely accessible services, prediction of potential vulnerabilities for any general network service and their estimated severity and finally policy resistance to attack propagation within the network. We then describe our rigorous validation experiments using real- life vulnerability data of the past 6 years from National Vulnerability Database (NVD) [10] to show the high accuracy and confidence of the proposed metrics. Some previous works have considered vulnerabilities using code analysis. However, as far as we know, this is the first work to study and analyze these metrics for network security evaluation using publicly available vulnerability information and security policy configuration.