A Conditional Probability Computation Method for Vulnerability Exploitation Based on CVSS
A Conditional Probability Computation Method for Vulnerability Exploitation Based on CVSS
复制标题
一种基于CVSS的漏洞利用条件概率计算方法
DOI:
--
复制
发表时间:
2017
期刊:
影响因子:
--
通讯作者:
Zhihong Tian
中科院分区:
文献类型:
--
作者:
Hua Zhang;Fang Lou;Yunsheng Fu;Zhihong Tian
Computing the probability of vulnerability exploitation in Bayesian attack graphs (BAGs) is a key process for the network security assessment. The conditional probability of vulnerability exploitation could be obtained from the exploitability of the NIST's Common Vulnerability Scoring System (CVSS). However, the method which N. Poolsappasit et al. proposed for computing conditional probability could be used only in the CVSS metric version v2.0, and can't be used in other two versions. In this paper, we present two methods for computing the conditional probability based on CVSS's other two metric versions, version 1.0 and version 3.0, respectively. Based on the CVSS, the conditional probability computation of vulnerability exploitation is complete by combining the method of N. Poolsappasit et al.