Vulnerability Modelling for Hybrid IT Systems

被引:18
|
作者
Ur-Rehman, Attiq [1 ]
Gondal, Iqbal [1 ]
Kamruzzuman, Joarder [1 ]
Jolfaei, Alireza [1 ]
机构
[1] Federat Univ Australia, Internet Commerce Secur Lab, Mt Helen, Australia
关键词
CVSS; IoT; vulnerability; supply chain; security;
D O I
10.1109/ICIT.2019.8755005
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Common vulnerability scoring system (CVSS) is an industry standard that can assess the vulnerability of nodes in traditional computer systems. The metrics computed by CVSS would determine critical nodes and attack paths. However, traditional IT security models would not fit IoT embedded networks due to distinct nature and unique characteristics of IoT systems. This paper analyses the application of CVSS for IoT embedded systems and proposes an improved vulnerability scoring system based on CVSS v3 framework. The proposed framework, named CVSSIoT, is applied to a realistic IT supply chain system and the results are compared with the actual vulnerabilities from the national vulnerability database. The comparison result validates the proposed model. CVSSIoT is not only effective, simple and capable of vulnerability evaluation for traditional IT system, but also exploits unique characteristics of IoT devices.
引用
收藏
页码:1186 / 1191
页数:6
相关论文
共 50 条
  • [1] Vulnerability Modelling for Hybrid Industrial Control System Networks
    Attiq Ur-Rehman
    Iqbal Gondal
    Joarder Kamruzzaman
    Alireza Jolfaei
    Journal of Grid Computing, 2020, 18 : 863 - 878
  • [2] Vulnerability Modelling for Hybrid Industrial Control System Networks
    Ur-Rehman, Attiq
    Gondal, Iqbal
    Kamruzzaman, Joarder
    Jolfaei, Alireza
    JOURNAL OF GRID COMPUTING, 2020, 18 (04) : 863 - 878
  • [3] Modelling and analysis of hybrid systems
    Engell, S
    MATHEMATICS AND COMPUTERS IN SIMULATION, 1998, 46 (5-6) : 445 - 464
  • [4] Modelling and analysis of hybrid systems
    Lehrst. F. Anlagensteuerungstechnik, Fachbereich Chemietechnik, Universität Dortmund, D-44221 Dortmund, Germany
    Math Comput Simul, 5-6 (445-464):
  • [5] Towards modelling of hybrid systems
    Wisniewski, Rafal
    PROCEEDINGS OF THE 45TH IEEE CONFERENCE ON DECISION AND CONTROL, VOLS 1-14, 2006, : 911 - 916
  • [6] FROM HYBRID SIMULATION TO HYBRID SYSTEMS MODELLING
    Mustafee, Navonil
    Powell, John H.
    2018 WINTER SIMULATION CONFERENCE (WSC), 2018, : 1430 - 1439
  • [7] Seismic vulnerability assessment and risk modelling of telecommunication systems
    Pakdel-Lahiji, Naghmeh
    Bastami, Morteza
    Sadeghi, Mehdi
    INTERNATIONAL JOURNAL OF CRITICAL INFRASTRUCTURES, 2016, 12 (04) : 295 - 310
  • [8] Compositional and uniform modelling of hybrid systems
    Benveniste, A
    PROCEEDINGS OF THE 35TH IEEE CONFERENCE ON DECISION AND CONTROL, VOLS 1-4, 1996, : 153 - 158
  • [9] Modelling and analysis of stochastic hybrid systems
    Hespanha, J. P.
    IEE PROCEEDINGS-CONTROL THEORY AND APPLICATIONS, 2006, 153 (05): : 520 - 535
  • [10] A Hybrid Approach for the Modelling of Complex Systems
    Christakis, Nicholas
    Cross, Mark
    Patel, Mayur K.
    Tuzun, Ugur
    JOURNAL OF ALGORITHMS & COMPUTATIONAL TECHNOLOGY, 2013, 7 (02) : 113 - 143