Vulnerability Modelling for Hybrid IT Systems

被引:18
|
作者
Ur-Rehman, Attiq [1 ]
Gondal, Iqbal [1 ]
Kamruzzuman, Joarder [1 ]
Jolfaei, Alireza [1 ]
机构
[1] Federat Univ Australia, Internet Commerce Secur Lab, Mt Helen, Australia
关键词
CVSS; IoT; vulnerability; supply chain; security;
D O I
10.1109/ICIT.2019.8755005
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Common vulnerability scoring system (CVSS) is an industry standard that can assess the vulnerability of nodes in traditional computer systems. The metrics computed by CVSS would determine critical nodes and attack paths. However, traditional IT security models would not fit IoT embedded networks due to distinct nature and unique characteristics of IoT systems. This paper analyses the application of CVSS for IoT embedded systems and proposes an improved vulnerability scoring system based on CVSS v3 framework. The proposed framework, named CVSSIoT, is applied to a realistic IT supply chain system and the results are compared with the actual vulnerabilities from the national vulnerability database. The comparison result validates the proposed model. CVSSIoT is not only effective, simple and capable of vulnerability evaluation for traditional IT system, but also exploits unique characteristics of IoT devices.
引用
收藏
页码:1186 / 1191
页数:6
相关论文
共 50 条
  • [41] Hybrid state approach for modelling electrical and mechanical systems
    Dogruel, M
    Adli, MA
    MATHEMATICAL AND COMPUTER MODELLING, 2005, 41 (6-7) : 759 - 771
  • [42] Modelling dependable systems using hybrid Bayesian networks
    Neil, Martin
    Tailor, Manesh
    Marquez, David
    Fenton, Norman
    Hearty, Peter
    RELIABILITY ENGINEERING & SYSTEM SAFETY, 2008, 93 (07) : 933 - 939
  • [43] Method of hybrid approximations for modelling of multidimensional nonlinear systems
    Torokhti, A
    Howlett, P
    Pearce, C
    MULTIDIMENSIONAL SYSTEMS AND SIGNAL PROCESSING, 2003, 14 (04) : 397 - 410
  • [44] Hybrid Modelling as a Tool for Analysis of Information Systems Security
    Lupin, Sergey
    Tun, Hein
    Thike, Aye Min
    Puschin, Mikhail
    PROCEEDINGS OF THE 2016 IEEE NORTH WEST RUSSIA SECTION YOUNG RESEARCHERS IN ELECTRICAL AND ELECTRONIC ENGINEERING CONFERENCE (ELCONRUSNW), 2016, : 259 - 261
  • [45] A hybrid modelling approach for separation systems involving distillation
    Schenk, M.
    Gani, R.
    Bogle, D.
    Pistikopoulos, E.N.
    Chemical Engineering Research and Design, 1999, 77 (06): : 519 - 534
  • [46] Hybrid modelling and simulation approaches for a class of mechatronic systems
    Oltean, Virginia Ecaterina
    Dobrescu, Radu
    Popescu, Dan
    Nicolae, Maximilian
    CONTROL ENGINEERING AND APPLIED INFORMATICS, 2010, 12 (01): : 47 - 54
  • [47] Modelling of oil production operation in the framework of hybrid systems
    Lemch, ES
    Guay, M
    Rudie, K
    PROCEEDINGS OF THE 41ST IEEE CONFERENCE ON DECISION AND CONTROL, VOLS 1-4, 2002, : 1595 - 1600
  • [48] Method of Hybrid Approximations for Modelling of Multidimensional Nonlinear Systems
    Anatoli Torokhti
    Phil Howlett
    Charles Pearce
    Multidimensional Systems and Signal Processing, 2003, 14 : 397 - 410
  • [49] Hybrid modelling: architecture for the solution of complex process systems
    Abbas, A
    Guevara, V
    Romagnoli, J
    EUROPEAN SYMPOSIUM ON COMPUTER AIDED PROCESS ENGINEERING - 12, 2002, 10 : 409 - 414
  • [50] Behavioural modelling and analysis of hybrid vehicle steering systems
    Mills, VD
    Wagner, JR
    PROCEEDINGS OF THE INSTITUTION OF MECHANICAL ENGINEERS PART D-JOURNAL OF AUTOMOBILE ENGINEERING, 2003, 217 (D5) : 349 - 361