课题基金 / 基金详情

A Vulnerability-Centric Approach to Network Security Metrics

A Vulnerability-Centric Approach to Network Security Metrics
以漏洞为中心的网络安全指标方法
批准号:
341840-2012
负责人:
Wang, Lingyu
金额:
$1.6万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2013
资助国家:
加拿大
项目状态:
已结题
起止时间:
2013-01-01 至 2014-12-31

项目摘要

项目成果

Wang, Lingyu的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
As today's critical infrastructures and enterprises increasingly rely on networked computer systems, the security of such systems becomes crucial to the economy and society. However, before we can improve the security of a network, it is desirable to be able to measure it, since "you cannot improve what you cannot measure". A network security metric is desirable since it will allow for a direct measurement of how secure a network currently is, and how secure it would be after introducing new security mechanisms or configuration changes. Such a capability will make the effort of network hardening a science rather than an art. Emerging efforts on network security metrics, including the Common Vulnerability Scoring System (CVSS-SIG) standard, typically assign numeric scores to vulnerabilities as their relative exploitability or likelihood. The assignment is usually based on known facts about each vulnerability (e.g., whether it requires an authenticated user account). Such approaches share several limitations. First, by considering vulnerabilities on an individual basis, a network security administrator could be misled in a situation where individual vulnerabilities scores are low but these vulnerabilities can be combined to compromise a critical resource. Second, the methodology is no longer applicable when considering zero day vulnerabilities about which we have no prior knowledge or experience, which in fact leads to a major criticism of existing efforts on security metrics, that is, unknown zero day vulnerabilities are not measurable. Third, the numerical scores assigned to vulnerabilities usually lack a well defined semantic, and are not generally related to other measures that can be easily interpreted by human analysts, such as time or dollars. The proposed research will address these pressing issues by proposing a novel vulnerability-centric approach to quantitatively modeling vulnerability information through security metrics.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2022
  • 负责人:
    Wang, Lingyu
  • 依托单位:
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
  • 批准号:
    RGPIN-2017-06686
  • 项目类别:
    Discovery Grants Program - Individual
  • 资助金额:
    $1.89万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2021
  • 负责人:
    Wang, Lingyu
  • 依托单位:
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
  • 批准号:
    544869-2018
  • 项目类别:
    Industrial Research Chairs
  • 资助金额:
    $9.11万
  • 财政年份:
    2020
  • 负责人:
    Wang, Lingyu
  • 依托单位:
海外基金