Skip to main navigation Skip to search Skip to main content

Methodologies to develop quantitative risk evaluation metrics

  • Thaier K.A. Hamid
  • , Carsten Maple
  • , Paul Sant

Research output: Contribution to journalArticlepeer-review

5 Downloads (Pure)

Abstract

The goal of this work is to advance a new methodology to measure a severity cost for each host using the Common Vulnerability Scoring System (CVSS) based on base, temporal and environmental metrics by combining related sub-scores to produce a unique severity cost by modeling the problem's parameters in to a mathematical framework. We build our own CVSS Calculator using our equations to simplify the calculations of the vulnerabilities scores and to benchmark with other models. We design and develop a new approach to represent the cost assigned to each host by dividing the scores of the vulnerabilities to two main levels of privileges, user and root, and we classify these levels into operational levels to identify and calculate the severity cost of multi steps vulnerabilities. Finally we implement our framework on a simple network, using Nessus scanner as tool to discover known vulnerabilities and to implement the results to build and represent our cost centric attack graph.
Original languageEnglish
Pages (from-to)17-24
JournalInternational Journal of Computer Applications
Volume48
Issue number14
DOIs
Publication statusPublished - 1 Jan 2012

Keywords

  • quantifying security

Fingerprint

Dive into the research topics of 'Methodologies to develop quantitative risk evaluation metrics'. Together they form a unique fingerprint.

Cite this