Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk

Identifying cyber risk hotspots: A framework for measuring temporal variance in computer network risk
复制标题

DOI:
10.1016/j.cose.2015.11.003
复制
发表时间:
2016-03
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
M. S. Awan;P. Burnap;O. Rana
M. S. Awan;P. Burnap;O. Rana
中科院分区:
其他
文献类型:
--
作者:
M. S. Awan;P. Burnap;O. Rana

文献摘要

被引文献

相似文献

现代计算机网络每天产生大量的行为系统日志。这样的网络包括许多具有互联网连接的计算机,并且许多访问Web和使用云服务的用户临时使用连接到网络的许多设备。由于网络中运行的各种服务和应用程序、与每个应用程序相关联的多个漏洞、与每个漏洞相关联的严重性以及网络罪犯不断变化的攻击媒介,衡量网络攻击的风险并确定大型计算机网络上的网络犯罪分子的最新作案手法可能很困难。在本文中,我们提出了一个框架来表示这些特征,从而能够执行实时网络枚举和流量分析,以便在特定时间点产生量化的风险度量。我们使用来自大学网络的数据验证了该方法,数据收集由462,787个实例组成,这些实例代表在144小时内测量的威胁。我们的分析可以推广到其他各种情况。
Modern computer networks generate significant volume of behavioural system logs on a daily basis. Such networks comprise many computers with Internet connectivity, and many users who access the Web and utilise Cloud services make use of numerous devices connected to the network on an ad-hoc basis. Measuring the risk of cyber attacks and identifying the most recent modus-operandi of cyber criminals on large computer networks can be difficult due to the wide range of services and applications running within the network, the multiple vulnerabilities associated with each application, the severity associated with each vulnerability, and the ever-changing attack vector of cyber criminals. In this paper we propose a framework to represent these features, enabling real-time network enumeration and traffic analysis to be carried out, in order to produce quantified measures of risk at specific points in time. We validate the approach using data from a University network, with a data collection consisting of 462,787 instances representing threats measured over a 144 hour period. Our analysis can be generalised to a variety of other contexts.