Quantitative Evaluation of Extensive Vulnerability Set Using Cost Benefit Analysis

被引:0
|
作者
Bansal, Urvashi [1 ]
Sikka, Geeta [2 ]
Awasthi, Lalit K. [3 ]
Bhargava, Bharat [4 ]
机构
[1] Natl Inst Technol, Dept Comp Sci & Engn, Jalandhar 144027, Punjab, India
[2] Natl Inst Technol, Dept Comp Sci & Engn, Delhi 110036, India
[3] Natl Inst Technol, Srinagar 246174, Uttarakhand, India
[4] Purdue Univ, W Lafayette, IN 47907 USA
关键词
Security; Organizations; Complexity theory; Internet of Things; Cost function; Prototypes; Standards organizations; Attack graph analysis; attack path cost; CVSS; IoT vulnerability analysis; network security; vulnerability risk assessment for IoT; ATTACK GRAPH; AUTHENTICATION PROTOCOL; SECURITY; IOT; FRAMEWORK; NETWORKS; PRIVACY;
D O I
10.1109/TDSC.2023.3253121
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The significant expansion in network size to support new paradigms such as cloud computing, IoT (Internet of Things), etc. together with the exponential increase in vulnerabilities has challenged the existing security mechanisms greatly. These challenges have opened many avenues for research in network security. However, while attack graphs play an important role in analyzing vulnerabilities, analyzing large attack graphs itself is a major issue. Therefore, it is necessary to extract only the critical part of the attack graph. Although technologies have been developed for attack path characterization, there is a lack of hybrid technology that can differentiate between similar behavior attack paths. We have proposed a cost-based path characterization technique that takes the attack node's vulnerability complexity into account and significantly reduces the number of vulnerabilities that need to be patched to avoid the major segment of attack graph. Moreover, we have used a real network prototype to validate the performance of the proposed scheme. The proposed scheme works well in cases where some vulnerabilities have similar risk scores. To the best of our knowledge, this is the first time that a cost-effective approach for attack path analysis has been proposed.
引用
收藏
页码:298 / 308
页数:11
相关论文
共 50 条
  • [21] Benefit-cost analysis using data envelopment analysis
    Womer, N. K.
    Bougnol, M. -L.
    Dula, J. H.
    Retzlaff-Roberts, D.
    ANNALS OF OPERATIONS RESEARCH, 2006, 145 (1) : 229 - 250
  • [22] Benefit-cost analysis using data envelopment analysis
    N. K. Womer
    M.-L. Bougnol
    J. H. Dula
    D. Retzlaff-Roberts
    Annals of Operations Research, 2006, 145 : 229 - 250
  • [23] Using the Kaldor-Hicks tableau format for cost-benefit analysis and policy evaluation
    Krutilla, K
    JOURNAL OF POLICY ANALYSIS AND MANAGEMENT, 2005, 24 (04) : 864 - 875
  • [24] Comparative evaluation of highways and railroads using life-cycle benefit-cost analysis
    Rattanakunuprakarn, Sarita
    Jin, Mingzhou
    Sussman, Michael
    Felix, Powell
    INTERNATIONAL JOURNAL OF SUSTAINABLE TRANSPORTATION, 2024, 18 (10) : 803 - 826
  • [25] Urban Development Project Evaluation Using Multi- Stakeholder Cost-Benefit Analysis
    Pramona, Retno W. D.
    Palupi, Lucky Dian
    Aditya, Rendy Bayu
    INTERNATIONAL REVIEW FOR SPATIAL PLANNING AND SUSTAINABLE DEVELOPMENT, 2022, 10 (04): : 240 - 259
  • [26] COST-BENEFIT EVALUATION
    CLARK, DC
    OLSEN, JB
    JOURNAL OF RESEARCH AND DEVELOPMENT IN EDUCATION, 1977, 10 (03): : 64 - 78
  • [27] THE EVALUATION OF A HOSTEL WARD - A CONTROLLED-STUDY USING MODIFIED COST-BENEFIT-ANALYSIS
    HYDE, C
    BRIDGES, K
    GOLDBERG, D
    LOWSON, K
    STERLING, C
    FARAGHER, B
    BRITISH JOURNAL OF PSYCHIATRY, 1987, 151 : 805 - 812
  • [28] Internalizing External Accident Costs in Safety Investment Evaluation Using Cost-Benefit Analysis
    Nikolova, Christina
    SUSTAINABILITY, 2024, 16 (19)
  • [29] Cost-benefit analysis: economic evaluation of policies and projects
    不详
    INVESTIGACIONES REGIONALES, 2009, (14): : 227 - 227
  • [30] EVALUATION OF LIMING OPERATIONS THROUGH BENEFIT-COST-ANALYSIS
    RIELY, PL
    ROCKLAND, DB
    WATER AIR AND SOIL POLLUTION, 1988, 41 (1-4): : 293 - 327