A Novel Security Model for Risk Assessment of Multi-Step Attacks in Computer Networks

Author(s):
Message:
Article Type:
Research/Original Article (دارای رتبه معتبر)
Abstract:

Risk Assessment and Management have always been considered as one of the most challenging issues of each organization. Risk assessment would not be possible but by risk analysis of the existing vulnerabilities. Vulnerability prioritization makes it possible for security administrators to have better understanding of the infrastructure. So they would be able to find the most perilous vulnerabilities to bring cost benefit trade off into practice. Nowadays most of the attacks are the multi-step ones, in which, attacker exploits more than one vulnerability in a specified manner. So, it would be inevitable to consider the interaction of vulnerabilities for risk assessment. In this relation, the most sophisticated difficulty would be lack of standards for finding the interrelationship between vast amount of vulnerabilities and risk analysis is being done only for one step attacks. So, in this paper, a method have been introduced for risk assessment of Multi-step attacks which improves the accuracy of the existing vulnerability scoring systems.

Language:
Persian
Published:
Journal of Iranian Association of Electrical and Electronics Engineers, Volume:18 Issue: 3, 2021
Pages:
153 to 166
https://magiran.com/p2324357  
دانلود و مطالعه متن این مقاله با یکی از روشهای زیر امکان پذیر است:
اشتراک شخصی
با عضویت و پرداخت آنلاین حق اشتراک یک‌ساله به مبلغ 1,390,000ريال می‌توانید 70 عنوان مطلب دانلود کنید!
اشتراک سازمانی
به کتابخانه دانشگاه یا محل کار خود پیشنهاد کنید تا اشتراک سازمانی این پایگاه را برای دسترسی نامحدود همه کاربران به متن مطالب تهیه نمایند!
توجه!
  • حق عضویت دریافتی صرف حمایت از نشریات عضو و نگهداری، تکمیل و توسعه مگیران می‌شود.
  • پرداخت حق اشتراک و دانلود مقالات اجازه بازنشر آن در سایر رسانه‌های چاپی و دیجیتال را به کاربر نمی‌دهد.
In order to view content subscription is required

Personal subscription
Subscribe magiran.com for 70 € euros via PayPal and download 70 articles during a year.
Organization subscription
Please contact us to subscribe your university or library for unlimited access!