• DocumentCode
    653880
  • Title

    CVSS-based security metrics for quantitative analysis of attack graphs

  • Author

    Keramati, Mahsa ; Akbari, A. ; Keramati, Mahsa

  • Author_Institution
    Comput. Sci. Dept., Semnan Univ., Semnan, Iran
  • fYear
    2013
  • fDate
    Oct. 31 2013-Nov. 1 2013
  • Firstpage
    178
  • Lastpage
    183
  • Abstract
    Attack graphs are efficient tools for detecting possible attacks in the network and their causes. By analyzing attack graphs and eliminating causes of attacks in the networks, we can immune networks against known intrusions. The main shortcoming of attack graphs is that they give no information about the damages of the possible attacks in the network. On the other hand by attack graphs, we can only analyze network security qualitatively. In this paper we propose a method that can measure the impact of each shown attack in the attack graph on the security parameters (Confidentiality, Availability and Integrity) of the network. In the proposed approach we have defined some security metrics by combining CVSS framework and attack graph. The main problem with the existing approaches is that, they cannot consider interrelation between vulnerabilities of the network efficiently. Our defined security metrics can address this issue and help us to assess network security quantitatively by analyzing attack graphs. By applying proposed security metrics on each network´s attack graph we can find the most perilous vulnerability in the network.
  • Keywords
    computer network security; graph theory; CVSS-based security metrics; common vulnerability scoring system; computer networks; network attack graph quantitative analysis; network security analysis; security parameters; Availability; Measurement; CVSS; attack graph; attack path; security loss; security metric; vulnerability;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer and Knowledge Engineering (ICCKE), 2013 3th International eConference on
  • Conference_Location
    Mashhad
  • Print_ISBN
    978-1-4799-2092-1
  • Type

    conf

  • DOI
    10.1109/ICCKE.2013.6682816
  • Filename
    6682816