Network Security Metrics

Network Security Metrics
复制标题

网络安全指标

DOI:
10.1007/978-3-319-66505-4
复制
发表时间:
2017
期刊:
Proceedings of the 5th Annual Symposium and Bootcamp on Hot Topics in the Science of Security
影响因子:
--
通讯作者:
A. Singhal
A. Singhal
中科院分区:
--
文献类型:
--
作者:
Lingyu Wang;S. Jajodia;A. Singhal

文献摘要

被引文献

相似文献

鉴于我们的社会对网络信息系统的依赖日益增加,应该衡量和改进这些系统的整体安全性。本章研究了将单个漏洞的 CVSS 分数组合成网络安全总体衡量标准的几种方法。首先,我们将 CVSS 基本分数转换为概率,然后沿着攻击图中的攻击路径传播这些概率,以获得总体指标,同时特别考虑攻击图中的循环。其次,我们表明,先前的方法隐含地假设各个漏洞的度量值是独立的,并且我们通过将攻击图及其分配的概率表示为贝叶斯网络来消除这种假设,然后通过贝叶斯推理得出总体度量值。最后,为了解决漏洞不断演变的性质,我们将先前的模型扩展到动态贝叶斯网络,以便我们可以对动态变化的网络的安全性做出推断。
Given the increasing dependence of our societies on networked information systems, the overall security of these systems should be measured and improved. This chapter examines several approaches to combining the CVSS scores of individual vulnerabilities into an overall measure for network security. First, we convert CVSS base scores into probabilities and then propagate such probabilities along attack paths in an attack graph in order to obtain an overall metric, while giving special considerations to cycles in the attack graph. Second, we show that the previous approach implicitly assumes the metric values of individual vulnerabilities to be independent, and we remove such an assumption by representing the attack graph and its assigned probabilities as a Bayesian network and then derive the overall metric value through Bayesian inferences. Finally, to address the evolving nature of vulnerabilities, we extend the previous model to dynamic Bayesian networks such that we can make inferences about the security of dynamically changing networks.