DocumentCode :
1778181
Title :
Considering temporal and environmental characteristics of vulnerabilities in network security risk assessment
Author :
Khosravi-Farmad, Masoud ; Rezaee, Razieh ; Bafghi, Abbas Ghaemi
Author_Institution :
Comput. Eng. Dept., Ferdowsi Univ. of Mashhad, Mashhad, Iran
fYear :
2014
fDate :
3-4 Sept. 2014
Firstpage :
186
Lastpage :
191
Abstract :
Assessing the overall security of a network requires a thorough understanding of interconnections between host vulnerabilities. In this paper, Bayesian attack graphs are used to model interconnections between vulnerabilities that enable the attacker to achieve a particular goal. In order to estimate the success probability of vulnerability exploitation, in addition to inherent characteristics of vulnerabilities, their temporal characteristics are also used to have more accurate estimation for current time of risk assessment. Since impacts of vulnerability exploitations in different environments varies from one organization to the other, environmental factors that affect the security goals such as confidentiality, integrity and availability are also considered which leads to a more precise assessment. Finally, the risk of each asset compromise is calculated by multiplying the unconditional probability of penetrating each asset in its resulted impact. The experimental results show that the proposed method effectively reduces the security risk in a test network in comparison to similar works.
Keywords :
Bayes methods; graph theory; risk management; security of data; Bayesian attack graphs; environmental characteristics; network security; risk assessment; temporal characteristics; vulnerability exploitation; Availability; Bayes methods; Measurement; Organizations; Risk management; Security; Attack graph; Bayesian networks; CVSS framework; Security risk assessment; Vulnerability;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Security and Cryptology (ISCISC), 2014 11th International ISC Conference on
Conference_Location :
Tehran
Type :
conf
DOI :
10.1109/ISCISC.2014.6994045
Filename :
6994045
Link To Document :
بازگشت