Vulnerability analysis for a quantitative security evaluation

Vulnerability analysis for a quantitative security evaluation
复制标题

DOI:
10.1109/esem.2009.5315969
复制
发表时间:
2009-10
期刊:
2009 3rd International Symposium on Empirical Software Engineering and Measurement
影响因子:
--
通讯作者:
G. Vache
G. Vache
中科院分区:
其他
文献类型:
--
作者:
G. Vache

文献摘要

被引文献

相似文献

本文通过概率分布对漏洞生命周期和漏洞利用的产生进行了定量描述。这项工作旨在帮助在考虑系统环境的情况下对信息系统安全进行定量评估。在本文中,我们关注两个环境因素:1)漏洞生命周期;2)攻击者行为。我们寻找能够对这些环境因素事件进行定量建模的概率分布及其参数。因此,为了获得精确的评估结果,需要使用真实数据来描述这些事件。为此,我们首先通过比较现有的可用漏洞数据库来选择一个合适的数据库。我们选择了开源漏洞数据库(Open Source Vulnerability DataBase)。在获取我们所需的数据之后,我们对与漏洞生命周期和攻击者行为相关的模型参数进行了定量评估。在此过程中,我们寻找漏洞类别的特性,以便更精确地定义我们的定量安全评估模型的参数化。
This paper presents the quantitative characterization of vulnerability life cycle and of exploit creation by probability distributions. This work aims at helping the production of quantitative measures of information system security considering system environment. In this paper, we focus on two environmental factors: 1) the vulnerability life cycle and 2) the attacker behaviour. We look for the probability distributions and their parameters that could model quantatively these environmental factor events. Thus, to obtain precise measures, it is needed to characterize these events using real data. For that purpose, we first selected an appropriate vulnerability database by comparing the existing and available ones. We choose the Open Source Vulnerability DataBase. After having brought back the data we need, we evaluate quantitatively the model parameters related to the vulnerability life cycle and the attacker behaviour. In doing so, we look for specificities of vulnerability categories to define the parameterization of our quantitative security evaluation modelling more precisely.