DocumentCode
1846404
Title
An efficient approach to assessing the risk of zero-day vulnerabilities
Author
Albanese, Massimiliano ; Jajodia, Sushil ; Singhal, Anoop ; Wang, Lingyu
Author_Institution
Center for Secure Information Systems, George Mason University, 4400 University Dr, Fairfax, VA 22030, U.S.A.
fYear
2013
fDate
29-31 July 2013
Firstpage
1
Lastpage
12
Abstract
Computer systems are vulnerable to both known and zero-day attacks. Although known attack patterns can be easily modeled, thus enabling the development of suitable hardening strategies, handling zero-day vulnerabilities is inherently difficult due to their unpredictable nature. Previous research has attempted to assess the risk associated with unknown attack patterns, and a suitable metric to quantify such risk, the k-zero-day safety metric, has been defined. However, existing algorithms for computing this metric are not scalable, and assume that complete zero-day attack graphs have been generated, which may be unfeasible in practice for large networks. In this paper, we propose a set of polynomial algorithms for estimating the k-zero-day safety of possibly large networks efficiently, without pre-computing the entire attack graph. We validate our approach through experiments, and show that the proposed algorithms are computationally efficient and accurate.
Keywords
Algorithm design and analysis; Communication networks; Measurement; Polynomials; Safety; Security; Upper bound; Attack Graphs; Vulnerability Analysis; Zero-Day Vulnerabilities;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Cryptography (SECRYPT), 2013 International Conference on
Conference_Location
Reykjavik, Iceland
Type
conf
Filename
7223168
Link To Document