Vulnerability Modelling for Hybrid IT Systems

被引:18
|
作者
Ur-Rehman, Attiq [1 ]
Gondal, Iqbal [1 ]
Kamruzzuman, Joarder [1 ]
Jolfaei, Alireza [1 ]
机构
[1] Federat Univ Australia, Internet Commerce Secur Lab, Mt Helen, Australia
关键词
CVSS; IoT; vulnerability; supply chain; security;
D O I
10.1109/ICIT.2019.8755005
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Common vulnerability scoring system (CVSS) is an industry standard that can assess the vulnerability of nodes in traditional computer systems. The metrics computed by CVSS would determine critical nodes and attack paths. However, traditional IT security models would not fit IoT embedded networks due to distinct nature and unique characteristics of IoT systems. This paper analyses the application of CVSS for IoT embedded systems and proposes an improved vulnerability scoring system based on CVSS v3 framework. The proposed framework, named CVSSIoT, is applied to a realistic IT supply chain system and the results are compared with the actual vulnerabilities from the national vulnerability database. The comparison result validates the proposed model. CVSSIoT is not only effective, simple and capable of vulnerability evaluation for traditional IT system, but also exploits unique characteristics of IoT devices.
引用
收藏
页码:1186 / 1191
页数:6
相关论文
共 50 条
  • [31] Modelling, analysis and control design of hybrid dynamical systems
    Voscek, Dominik
    Jadlovska, Anna
    Grigl'ak, Dominik
    JOURNAL OF ELECTRICAL ENGINEERING-ELEKTROTECHNICKY CASOPIS, 2019, 70 (03): : 176 - 186
  • [32] Editorial of the evolving and hybrid systems’ modelling special issue
    Lazaros Iliadis
    Ilias Maglogiannis
    Evolving Systems, 2021, 12 : 1 - 2
  • [33] A hybrid modelling approach for separation systems involving distillation
    Schenk, M
    Gani, R
    Bogle, D
    Pistikopoulos, EN
    CHEMICAL ENGINEERING RESEARCH & DESIGN, 1999, 77 (A6): : 519 - 534
  • [34] Hybrid modelling of transportation systems by means of Petri nets
    Di Febbraro, A
    Sacone, S
    1998 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS, VOLS 1-5, 1998, : 131 - 135
  • [35] General stochastic hybrid systems: Modelling and optimal control
    Bujorianu, ML
    Lygeros, J
    2004 43RD IEEE CONFERENCE ON DECISION AND CONTROL (CDC), VOLS 1-5, 2004, : 1872 - 1877
  • [36] Hybrid systems: Modelling and analysis using emergent dynamics
    Ronkko, Mauno
    NONLINEAR ANALYSIS-HYBRID SYSTEMS, 2007, 1 (04) : 560 - 576
  • [37] A compositional modelling and analysis framework for stochastic hybrid systems
    Hahn, Ernst Moritz
    Hartmanns, Arnd
    Hermanns, Holger
    Katoen, Joost-Pieter
    FORMAL METHODS IN SYSTEM DESIGN, 2013, 43 (02) : 191 - 232
  • [38] Editorial of the evolving and hybrid systems' modelling special issue
    Iliadis, Lazaros
    Maglogiannis, Ilias
    EVOLVING SYSTEMS, 2021, 12 (01) : 1 - 2
  • [39] Modelling and Verifying Communication Failure of Hybrid Systems in HCSP
    Wang, Shuling
    Nielson, Flemming
    Nielson, Hanne Riis
    Zhan, Naijun
    COMPUTER JOURNAL, 2017, 60 (08): : 1111 - 1130
  • [40] An interactive graphical environment for modelling and simulation of hybrid systems
    Chen, LM
    Bechkoum, K
    ESM'99 - MODELLING AND SIMULATION: A TOOL FOR THE NEXT MILLENNIUM, VOL II, 1999, : 42 - 46