Quantifying security risk is an important and yet difficult task in enterprise network security management. Even though metrics exist for individual vulnerabilities, such as CVSS, there is currently no standard way of aggregating such metrics. We developed a quantitative model that can be used to aggregate vulnerability metrics in an enterprise network, with a sound computation model. The result of the aggregation is quantitative metrics that measure the likelihood breaches can occur within a given network configuration, taking into consideration the effects of all the inter-plays between all the vulnerabilities. In order to validate the effectiveness of this approach to realistic networks, we present the empirical study results of the approach on a number of system configurations. We used a real network as the test bed to demonstrate the utility of the approach. We show that the sound computation model is crucial for interpreting the metric result.
August 14, 2013
Abstract: An Empirical Study of a Vulnerability Metric Aggregation Model
Comments Off on Abstract: An Empirical Study of a Vulnerability Metric Aggregation Model
No Comments
No comments yet.
RSS feed for comments on this post.
Sorry, the comment form is closed at this time.