A model for quantitative security measurement and prioritisation of vulnerability mitigation

  • Authors:
  • Anshu Tripathi;Umesh Kumar Singh

  • Affiliations:
  • Department of Information Technology, Mahakal Institute of Technology, Ujjain 456010, Madhya Pradesh, India;Institute of Computer Science, Vikram University, Ujjain 456010, Madhya Pradesh, India

  • Venue:
  • International Journal of Security and Networks
  • Year:
  • 2013

Quantified Score

Hi-index 0.00

Visualization

Abstract

Quantitative security measurement is an essential step in managing security proactively. This measurement can help system administrator in making optimal decisions about mitigation of security risks posed by presence of vulnerabilities. Quantifying security risks using security metrics is an important and yet challenging task, as metrics exists for individual vulnerabilities but how to aggregate these metrics is still an unresolved issue. In this paper, we propose a quantitative security measurement model that measures security level of hosts in the network by aggregating risk levels of vulnerabilities in a meaningful manner. Further, proposed model guides system administrator in prioritising vulnerability mitigation by evaluating relative risk level of vulnerabilities in the network. Proposed model produces quantitative security metrics that provide rapid and consistent security measurement, hence aid in automated and reasonable security management. A case study is presented to demonstrate the efficacy of proposed model.