Abstract:
Because of the large scale and wide variety of vulnerabilities under network scenarios, administrator using isolated scoring method for the scanned vulnerability can hard...Show MoreMetadata
Abstract:
Because of the large scale and wide variety of vulnerabilities under network scenarios, administrator using isolated scoring method for the scanned vulnerability can hardly figure out an economic and practical vulnerability patching strategy from numerous choices, due to the lack of consideration on the dynamic status and logic relations among exploits. In this paper, we estimated the influential level of vulnerabilities under the dynamic network scenario through a “hybrid” ranking approach, which is a combination of the low-level rating for vulnerability instances and high-level evaluation for the whole network system. To demonstrate both the applicability and accuracy of our approach, a hybrid ranking engine (HRE) is built. Results show that our approach can help make better operations to harden the network security under network scenarios.
Published in: 10th International Conference on Information Science, Signal Processing and their Applications (ISSPA 2010)
Date of Conference: 10-13 May 2010
Date Added to IEEE Xplore: 18 October 2010
ISBN Information: