Quantitative Evaluation of Extensive Vulnerability Set Using Cost Benefit Analysis

被引:0
|
作者
Bansal, Urvashi [1 ]
Sikka, Geeta [2 ]
Awasthi, Lalit K. [3 ]
Bhargava, Bharat [4 ]
机构
[1] Natl Inst Technol, Dept Comp Sci & Engn, Jalandhar 144027, Punjab, India
[2] Natl Inst Technol, Dept Comp Sci & Engn, Delhi 110036, India
[3] Natl Inst Technol, Srinagar 246174, Uttarakhand, India
[4] Purdue Univ, W Lafayette, IN 47907 USA
关键词
Security; Organizations; Complexity theory; Internet of Things; Cost function; Prototypes; Standards organizations; Attack graph analysis; attack path cost; CVSS; IoT vulnerability analysis; network security; vulnerability risk assessment for IoT; ATTACK GRAPH; AUTHENTICATION PROTOCOL; SECURITY; IOT; FRAMEWORK; NETWORKS; PRIVACY;
D O I
10.1109/TDSC.2023.3253121
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The significant expansion in network size to support new paradigms such as cloud computing, IoT (Internet of Things), etc. together with the exponential increase in vulnerabilities has challenged the existing security mechanisms greatly. These challenges have opened many avenues for research in network security. However, while attack graphs play an important role in analyzing vulnerabilities, analyzing large attack graphs itself is a major issue. Therefore, it is necessary to extract only the critical part of the attack graph. Although technologies have been developed for attack path characterization, there is a lack of hybrid technology that can differentiate between similar behavior attack paths. We have proposed a cost-based path characterization technique that takes the attack node's vulnerability complexity into account and significantly reduces the number of vulnerabilities that need to be patched to avoid the major segment of attack graph. Moreover, we have used a real network prototype to validate the performance of the proposed scheme. The proposed scheme works well in cases where some vulnerabilities have similar risk scores. To the best of our knowledge, this is the first time that a cost-effective approach for attack path analysis has been proposed.
引用
收藏
页码:298 / 308
页数:11
相关论文
共 50 条
  • [41] Cost-benefit analysis using CVM for IT investments
    Kaneda, S
    Ishitani, S
    KNOWLEDGE-BASED SOFTWARE ENGINEERING, 2000, 62 : 211 - 218
  • [42] Cost–benefit analysis
    Grant Miura
    Nature Chemical Biology, 2018, 14 : 903 - 903
  • [43] COST BENEFIT ANALYSIS
    PRYNN, PJ
    CHEMISTRY & INDUSTRY, 1970, (01) : 9 - &
  • [44] Cost benefit analysis of extensive green roofs under tropic humid conditions in Villahermosa, Mexico
    de la Cruz-Uribe, Adriana
    Jesus-Castaneda, Miguel Angel
    Bolivar-Fuentes, Rosa Cristina
    Laines-Canepa, Jose Ramon
    Hernandez-Barajas, Jose Roberto
    ECOSISTEMAS Y RECURSOS AGROPECUARIOS, 2023, 10 (01):
  • [45] Implementation of quantitative risk and cost-benefit analysis in an aging offshore facility
    Lazuardi, Khoir
    Kumaraningrum, Anggraini Ratih
    Hermansyah, Heri
    PROCESS SAFETY PROGRESS, 2024, 43 (S1) : S116 - S127
  • [46] Problems of the poor set to face cost–benefit treatment
    Jim Giles
    Nature, 2004, 428 : 110 - 110
  • [47] Hierarchical Quantitative Evaluation of Vulnerability Exploitability
    Sheng Yi
    2018 EIGHTH INTERNATIONAL CONFERENCE ON INSTRUMENTATION AND MEASUREMENT, COMPUTER, COMMUNICATION AND CONTROL (IMCCC 2018), 2018, : 115 - 118
  • [48] A Method for Vulnerability Database Quantitative Evaluation
    Tan, Tiantian
    Wang, Baosheng
    Tang, Yong
    Zhou, Xu
    Han, Jingwen
    CMC-COMPUTERS MATERIALS & CONTINUA, 2019, 61 (03): : 1129 - 1144
  • [49] Risk-Based Evaluation of Improvements in Drinking Water Treatment Using Cost-Benefit Analysis
    Skold, Nils-Petter
    Bergion, Viktor
    Lindhe, Andreas
    Keucken, Alexander
    Rosen, Lars
    WATER, 2022, 14 (05)
  • [50] Economic Evaluation of Green Building Based On Cost-Benefit Analysis
    Liu, Y.
    Lu, H. M.
    CRIOCM2009: INTERNATIONAL SYMPOSIUM ON ADVANCEMENT OF CONSTRUCTION MANAGEMENT AND REAL ESTATE, VOLS 1-6, 2009, : 464 - 469