作者
Urvashi Garg, Geeta Sikka, Lalit K Awasthi
发表日期
2018/8/1
期刊
Computers & Security
卷号
77
页码范围
349-359
出版商
Elsevier Advanced Technology
简介
The proliferated complexity of network size together with the expeditious development of software applications and their numerous vulnerabilities, security hardening is becoming a considerable challenge for security experts. Although various techniques were already present till date for security analysis, the majority of works focused on individual vulnerability analysis. Attackers do not necessarily compromise a single vulnerability on only one machine, but they can continue exploiting other vulnerabilities by using the resources of the compromised machine. Individual vulnerability analysis may not work well in such situations. This paper bridges the gap between chained vulnerabilities and their analysis. In this work, we have developed a methodology to prioritize individual vulnerability as well as attack paths. The existing CVSS score based scheme has been modified to calculate risk score of individual …
引用总数
201920202021202220232024226831