首页> 外文会议>International Conference on Advances in Big Data, Computing and Data Communication Systems >CVSS Metric-Based Analysis, Classification and Assessment of Computer Network Threats and Vulnerabilities
【24h】

CVSS Metric-Based Analysis, Classification and Assessment of Computer Network Threats and Vulnerabilities

机译:CVSS基于度量的分析,分类和评估计算机网络威胁和漏洞

获取原文

摘要

This paper provides a Common Vulnerability Scoring System (CVSS) metric-based technique for classifying and analysing the prevailing Computer Network Security Vulnerabilities and Threats (CNSVT). The problem that is addressed in this paper, is that, at the time of writing this paper, there existed no effective approaches for analysing and classifying CNSVT for purposes of assessments based on CVSS metrics. The authors of this paper have achieved this by generating a CVSS metric-based dynamic Vulnerability Analysis Classification Countermeasure (VACC) criterion that is able to rank vulnerabilities. The CVSS metric-based VACC has allowed the computation of vulnerability Similarity Measure (VSM) using the Hamming and Euclidean distance metric functions. Nevertheless, the CVSS-metric based on VACC also enabled the random measuring of the VSM for a selected number of vulnerabilities based on the [Ma-Ma], [Ma-Mi], [Mi-Ci], [Ma-Ci] ranking score. This is a technique that is aimed at allowing security experts to be able to conduct proper vulnerability detection and assessments across computer-based networks based on the perceived occurrence by checking the probability that given threats will occur or not. The authors have also proposed high-level countermeasures of the vulnerabilities that have been listed. The authors have evaluated the CVSS-metric based VACC and the results are promising. Based on this technique, it is worth noting that these propositions can help in the development of stronger computer and network security tools.
机译:本文提供了一个通用安全漏洞评分系统(CVSS)进行分类和分析当时的计算机网络安全漏洞和威胁(CNSVT)基于度量的技术。这是本文要解决的问题是,在写作本文的时候,存在着分析和基于CVSS指标评估的目的进行分类CNSVT没有有效的办法。本文的作者已经通过生成CVSS的度量为基础的动态弱点分析分类对策(VACC)标准,它能够排名漏洞实现这一点。的CVSS度量基于VACC已经允许使用汉明和欧几里德距离度量的功能的脆弱性相似性度量(VSM)的计算。尽管如此,CVSS度量基于VACC也使VSM的随机测量基于所述[马麻],[马-M-1],[米次],[麻次]排名漏洞选定数目的分数。这是一个旨在使安全专家能够通过检查给出的威胁会发生与否的可能性进行跨基于感知发生基于计算机的网络,正确的漏洞检测和评估的技术。作者还提出,已列出的漏洞的高级对策。作者们评估了CVSS度量基于VACC,结果是有希望的。基于该技术,值得注意的是,这些主张可以在更强的计算机和网络安全工具的发展提供帮助。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号