A hybrid ranking approach to estimate vulnerability for dynamic attacks

  • Authors:
  • Feng Zhao;Heqing Huang;Hai Jin;Qin Zhang

  • Affiliations:
  • School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China and Services Computing Technology and System Lab, Wuhan 430074, China and Cluster and ...;School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China;School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China and Services Computing Technology and System Lab, Wuhan 430074, China and Cluster and ...;School of Computer Science and Technology, Huazhong University of Science and Technology, Wuhan 430074, China and Services Computing Technology and System Lab, Wuhan 430074, China and Cluster and ...

  • Venue:
  • Computers & Mathematics with Applications
  • Year:
  • 2011

Quantified Score

Hi-index 0.09

Visualization

Abstract

To enhance security in dynamic networks, it is important to evaluate the vulnerabilities and offer economic and practical patching strategy since vulnerability is the major driving force for attacks. In this paper, a hybrid ranking approach is presented to estimate vulnerabilities under the dynamic scenarios, which is a combination of low-level rating for vulnerability instances and high-level evaluation for the security level of the network system. Moreover, a novel quantitative model, an adapted attack graph, is also proposed to escaping isolated scoring, which takes the dynamic and logic relations among exploits into account, and significantly benefits to vulnerability analysis. To validate applicability and performance of our approach, a hybrid ranking case is implemented as experimental platform. The ranking results show that our approach differentiates the influential levels among vulnerabilities under dynamic attacking scenarios and economically enhances the security of network system.