Vulnerability Modelling for Hybrid IT Systems

被引:18
|
作者
Ur-Rehman, Attiq [1 ]
Gondal, Iqbal [1 ]
Kamruzzuman, Joarder [1 ]
Jolfaei, Alireza [1 ]
机构
[1] Federat Univ Australia, Internet Commerce Secur Lab, Mt Helen, Australia
关键词
CVSS; IoT; vulnerability; supply chain; security;
D O I
10.1109/ICIT.2019.8755005
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Common vulnerability scoring system (CVSS) is an industry standard that can assess the vulnerability of nodes in traditional computer systems. The metrics computed by CVSS would determine critical nodes and attack paths. However, traditional IT security models would not fit IoT embedded networks due to distinct nature and unique characteristics of IoT systems. This paper analyses the application of CVSS for IoT embedded systems and proposes an improved vulnerability scoring system based on CVSS v3 framework. The proposed framework, named CVSSIoT, is applied to a realistic IT supply chain system and the results are compared with the actual vulnerabilities from the national vulnerability database. The comparison result validates the proposed model. CVSSIoT is not only effective, simple and capable of vulnerability evaluation for traditional IT system, but also exploits unique characteristics of IoT devices.
引用
收藏
页码:1186 / 1191
页数:6
相关论文
共 50 条
  • [21] A framework of fuzzy hybrid systems for modelling and control
    Cheng, Shu
    Dong, Ruijun
    Pedrycz, Witold
    INTERNATIONAL JOURNAL OF GENERAL SYSTEMS, 2010, 39 (02) : 165 - 176
  • [22] Implicit representation for the modelling of hybrid dynamic systems
    Lu, Yu-Ping
    Buisson, Jean
    Cormerais, Herve
    Chinese Journal of Aeronautics, 2000, 13 (01) : 45 - 50
  • [23] HYPE Applied to the Modelling of Hybrid Biological Systems
    Galpin, Vashti
    Hillston, Jane
    Bortolussi, Luca
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2008, 218 (0C) : 33 - 51
  • [25] Hybrid modelling and constrained control of juggling systems
    Hoai Nam Nguyen
    Olaru, Sorin
    INTERNATIONAL JOURNAL OF SYSTEMS SCIENCE, 2013, 44 (02) : 306 - 320
  • [26] Tutorial introduction to the modelling and control of hybrid systems
    Balbis, Luisella
    Ordys, Andrzej W.
    Grimble, Michael J.
    Pang, Yan
    INTERNATIONAL JOURNAL OF MODELLING IDENTIFICATION AND CONTROL, 2007, 2 (04) : 259 - 272
  • [27] Hybrid modelling and emulation of mem-systems
    Kolka, Zdenek
    Biolek, Dalibor
    Biolkova, Viera
    INTERNATIONAL JOURNAL OF NUMERICAL MODELLING-ELECTRONIC NETWORKS DEVICES AND FIELDS, 2012, 25 (03) : 216 - 225
  • [28] On synergies of cyber and physical security modelling in vulnerability assessment of railway systems
    Marrone, Stefano
    Rodriguez, Ricardo J.
    Nardone, Roberto
    Flammini, Francesco
    Vittorini, Valeria
    COMPUTERS & ELECTRICAL ENGINEERING, 2015, 47 : 275 - 285
  • [29] A Compositional Modelling and Verification Framework for Stochastic Hybrid Systems
    Wang, Shuling
    Zhan, Naijun
    Zhang, Lijun
    FORMAL ASPECTS OF COMPUTING, 2017, 29 (04) : 751 - 775
  • [30] A compositional modelling and analysis framework for stochastic hybrid systems
    Ernst Moritz Hahn
    Arnd Hartmanns
    Holger Hermanns
    Joost-Pieter Katoen
    Formal Methods in System Design, 2013, 43 : 191 - 232