A Vulnerability-Centric Approach to Network Security Metrics

以漏洞为中心的网络安全指标方法

基本信息

  • 批准号:
    341840-2012
  • 负责人:
  • 金额:
    $ 1.6万
  • 依托单位:
  • 依托单位国家:
    加拿大
  • 项目类别:
    Discovery Grants Program - Individual
  • 财政年份:
    2016
  • 资助国家:
    加拿大
  • 起止时间:
    2016-01-01 至 2017-12-31
  • 项目状态:
    已结题

项目摘要

As today's critical infrastructures and enterprises increasingly rely on networked computer systems, the security of such systems becomes crucial to the economy and society. However, before we can improve the security of a network, it is desirable to be able to measure it, since "you cannot improve what you cannot measure". A network security metric is desirable since it will allow for a direct measurement of how secure a network currently is, and how secure it would be after introducing new security mechanisms or configuration changes. Such a capability will make the effort of network hardening a science rather than an art. Emerging efforts on network security metrics, including the Common Vulnerability Scoring System (CVSS-SIG) standard, typically assign numeric scores to vulnerabilities as their relative exploitability or likelihood. The assignment is usually based on known facts about each vulnerability (e.g., whether it requires an authenticated user account). Such approaches share several limitations. First, by considering vulnerabilities on an individual basis, a network security administrator could be misled in a situation where individual vulnerabilities scores are low but these vulnerabilities can be combined to compromise a critical resource. Second, the methodology is no longer applicable when considering zero day vulnerabilities about which we have no prior knowledge or experience, which in fact leads to a major criticism of existing efforts on security metrics, that is, unknown zero day vulnerabilities are not measurable. Third, the numerical scores assigned to vulnerabilities usually lack a well defined semantic, and are not generally related to other measures that can be easily interpreted by human analysts, such as time or dollars. The proposed research will address these pressing issues by proposing a novel vulnerability-centric approach to quantitatively modeling vulnerability information through security metrics.
随着当今的关键基础设施和企业越来越依赖于联网的计算机系统,这种系统的安全性对于经济和社会变得至关重要。然而,在我们能够提高网络的安全性之前,最好能够对其进行测量,因为“你无法改善你无法测量的东西”。网络安全度量是期望的,因为它将允许直接测量网络当前有多安全,以及在引入新的安全机制或配置改变之后它将有多安全。这种能力将使网络强化成为一门科学,而不是一门艺术。网络安全指标方面的新兴努力,包括通用漏洞评分系统(CVSS-SIG)标准,通常会为漏洞分配数字分数,作为其相对可利用性或可能性。分配通常基于关于每个漏洞的已知事实(例如,是否需要认证的用户帐户)。这种方法有几个局限性。首先,通过在个体基础上考虑漏洞,网络安全管理员可能在个体漏洞分数较低但这些漏洞可以组合以危害关键资源的情况下被误导。其次,当考虑我们没有先验知识或经验的零日漏洞时,该方法不再适用,这实际上导致了对现有安全指标的主要批评,即未知的零日漏洞是不可测量的。第三,分配给漏洞的数值分数通常缺乏定义良好的语义,并且通常与人类分析师可以轻松解释的其他指标(如时间或美元)无关。拟议的研究将解决这些紧迫的问题,提出了一种新的以安全性为中心的方法,通过安全指标定量建模的漏洞信息。

项目成果

期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Wang, Lingyu其他文献

The mechanism of Co oxyhydroxide nano-islands deposited on a Pt surface to promote the oxygen reduction reaction at the cathode of fuel cells.
  • DOI:
    10.1039/d0ra08645b
  • 发表时间:
    2020-12-17
  • 期刊:
  • 影响因子:
    3.9
  • 作者:
    Lu, Jinghao;Yang, Libin;Guo, Wei;Xiao, Songtao;Wang, Lingyu;OuYang, Yinggen;Gao, Peng
  • 通讯作者:
    Gao, Peng
Integrating network pharmacology and experimental studies for uncovering the molecular mechanisms of Dioscorea bulbifera L. in the treatment of thyroid cancer.
  • DOI:
    10.1016/j.heliyon.2023.e18886
  • 发表时间:
    2023-08
  • 期刊:
  • 影响因子:
    4
  • 作者:
    Liu, Ziqi;Zhong, Lian;Wang, Lingyu;Li, Meiyan;Chen, Chao
  • 通讯作者:
    Chen, Chao
microRNA regulation in an ancient obligate endosymbiosis
  • DOI:
    10.1111/mec.14464
  • 发表时间:
    2018-04-01
  • 期刊:
  • 影响因子:
    4.9
  • 作者:
    Feng, Honglin;Wang, Lingyu;Wilson, Alex C. C.
  • 通讯作者:
    Wilson, Alex C. C.
A taint based approach for automatic reverse engineering of gray-box file formats
一种基于污点的灰盒文件格式自动逆向工程方法
Synthesis and Characterization of g-C(3)N(4)/Ag(3)PO(4)/TiO(2)/PVDF Membrane with Remarkable Self-Cleaning Properties for Rhodamine B Removal.

Wang, Lingyu的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Wang, Lingyu', 18)}}的其他基金

Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
  • 批准号:
    RGPIN-2017-06686
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
  • 批准号:
    RGPIN-2017-06686
  • 财政年份:
    2021
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
NSERC/爱立信软件定义网络和网络功能虚拟化安全工业研究主席:合规驱动的监控、检测和缓解
  • 批准号:
    544869-2018
  • 财政年份:
    2021
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Industrial Research Chairs
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
NSERC/爱立信软件定义网络和网络功能虚拟化安全工业研究主席:合规驱动的监控、检测和缓解
  • 批准号:
    544869-2018
  • 财政年份:
    2020
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Industrial Research Chairs
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
  • 批准号:
    RGPIN-2017-06686
  • 财政年份:
    2020
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
NSERC/Ericsson Industrial Research Chair in Software-Defined Networking and Network Functions Virtualization Security: Compliance-Driven Monitoring, Detection, and Mitigation
NSERC/爱立信软件定义网络和网络功能虚拟化安全工业研究主席:合规驱动的监控、检测和缓解
  • 批准号:
    544869-2018
  • 财政年份:
    2019
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Industrial Research Chairs
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
  • 批准号:
    RGPIN-2017-06686
  • 财政年份:
    2019
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
Improving the Resilience of Computing Infrastructures against Zero Day Attacks through Quantitative Threat Modeling and Network Hardening
通过定量威胁建模和网络强化提高计算基础设施抵御零日攻击的弹性
  • 批准号:
    RGPIN-2017-06686
  • 财政年份:
    2018
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
Auditing and monitoring the security of NFV and SDN-based cloud environments
审计和监控基于 NFV 和 SDN 的云环境的安全性
  • 批准号:
    517415-2017
  • 财政年份:
    2018
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Collaborative Research and Development Grants
Auditing and monitoring the security of NFV and SDN-based cloud environments
审计和监控基于 NFV 和 SDN 的云环境的安全性
  • 批准号:
    517415-2017
  • 财政年份:
    2017
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Collaborative Research and Development Grants

相似海外基金

UK Privacy Enhancing Technologies Challenge Prize - Phase 3 Project title: Pandemic Response Modelling with Privacy Enhancing Technology: a place-centric approach
英国隐私增强技术挑战奖 - 第 3 阶段 项目名称:利用隐私增强技术进行流行病响应建模:以地点为中心的方法
  • 批准号:
    900262
  • 财政年份:
    2023
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Collaborative R&D
A Patient-Centric Approach to Advance Functional Precision Oncology
以患者为中心的方法推进功能性精准肿瘤学
  • 批准号:
    10721205
  • 财政年份:
    2023
  • 资助金额:
    $ 1.6万
  • 项目类别:
Improving the social acceptance of smart technologies: A people-centric approach for sustainable smart waste management and smart mobility technologies
提高智能技术的社会接受度:以人为本的可持续智能废物管理和智能移动技术方法
  • 批准号:
    23K11548
  • 财政年份:
    2023
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
A Quest for Harmony between Privacy and Personalization: A User-Centric Approach
寻求隐私与个性化之间的和谐:以用户为中心的方法
  • 批准号:
    RGPIN-2018-05884
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Discovery Grants Program - Individual
Pandemic Response Modelling with Privacy Enhancing Technology: a place-centric approach
采用隐私增强技术的流行病响应建模:以地点为中心的方法
  • 批准号:
    10048012
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
    CR&D Bilateral
Collaborative Research: SHF: Small: Rethinking Performance Variation for Emerging Applications - An Application-centric and Cross-layer Approach
协作研究:SHF:小型:重新思考新兴应用程序的性能变化 - 以应用程序为中心的跨层方法
  • 批准号:
    2134202
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Standard Grant
Collaborative Research: SHF: Small: Rethinking Performance Variation for Emerging Applications - An Application-centric and Cross-layer Approach
协作研究:SHF:小型:重新思考新兴应用程序的性能变化 - 以应用程序为中心的跨层方法
  • 批准号:
    2134203
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
    Standard Grant
Foundational Elements of an Alternate Scientific Approach to Developing Veteran-centric Precision Cognitive Restoration Interventions
开发以退伍军人为中心的精确认知恢复干预措施的替代科学方法的基本要素
  • 批准号:
    10542362
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
Foundational Elements of an Alternate Scientific Approach to Developing Veteran-centric Precision Cognitive Restoration Interventions
开发以退伍军人为中心的精确认知恢复干预措施的替代科学方法的基本要素
  • 批准号:
    10368616
  • 财政年份:
    2022
  • 资助金额:
    $ 1.6万
  • 项目类别:
data-driven approach to occupant-centric building operations
以数据驱动的方法实现以居住者为中心的建筑运营
  • 批准号:
    567056-2021
  • 财政年份:
    2021
  • 资助金额:
    $ 1.6万
  • 项目类别:
    University Undergraduate Student Research Awards
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了