作者
Tingting Wang, Qiujian Lv, Bo Hu, Degang Sun
发表日期
2020/7/17
研讨会论文
2020 IEEE 10th International Conference on Electronics Information and Emergency Communication (ICEIEC)
页码范围
289-294
出版商
IEEE
简介
The risk assessment model of network systems is designed to provide quantifiable evidence to assist security administrators in choosing appropriate defend methods. Most models measure the overall risk by combining CVSS base scores of system vulnerabilities. However, they merely consider the impact of dynamic risk factors including attacker capability and evolutions of vulnerabilities. To address this issue, we propose a CVSS based Multi-Factor dynamic risk assessment Model, CMFM. It uses attack paths to model an attacker’s capability, which is thus used to estimate the successful probabilities about vulnerability exploitations. Besides, we exploit both static and time-variant factors of vulnerabilities to produce a better estimation result. The final system risk assessment can then be accessed via a Bayesian attack graph. We evaluate the proposed model in two scenarios, all of which demonstrate that CMFM …
引用总数
学术搜索中的文章
T Wang, Q Lv, B Hu, D Sun - 2020 IEEE 10th International Conference on …, 2020