期刊文献+

Dependence-Induced Risk: Security Metrics and Their Measurement Framework 被引量:2

Dependence-Induced Risk: Security Metrics and Their Measurement Framework
下载PDF
导出
摘要 Despite the tremendous effort made by industry and academia,we are still searching for metrics that can characterize Cyberspace and system security risks. In this paper,we study the class of security risks that are inherent to the dependence structure in software with vulnerabilities and exhibit a "cascading" effect. We present a measurement framework for evaluating these metrics,and report a preliminary case study on evaluating the dependence-induced security risks in the Apache HTTP Server. The experiment results show that our framework can not only clearly analyze the root cause of the security risks but also quantitatively evaluate the attack consequence of the risks. Despite the tremendous effort made by industry and academia,we are still searching for metrics that can characterize Cyberspace and system security risks. In this paper,we study the class of security risks that are inherent to the dependence structure in software with vulnerabilities and exhibit a "cascading" effect. We present a measurement framework for evaluating these metrics,and report a preliminary case study on evaluating the dependence-induced security risks in the Apache HTTP Server. The experiment results show that our framework can not only clearly analyze the root cause of the security risks but also quantitatively evaluate the attack consequence of the risks.
出处 《China Communications》 SCIE CSCD 2016年第11期119-128,共10页 中国通信(英文版)
基金 supported by Natural Science Foundation of China under award No.61303024 Natural Science Foundation of Jiangsu Province under award No.BK20130372 National 973 Program of China under award No.2014CB340600 National High Tech 863 Program of China under award No.2015AA016002 supported by Natural Science Foundation of China under award No.61272452 supported in part by ARO Grant # W911NF-12-1-0286 and NSF Grant #1111925
关键词 Cyberspace security security metrics exploitability surface attack conse quence risk assessment 安全风险评价 安全度量 框架 诱导 HTTP服务器 Apache 定量评估 网络空间
  • 相关文献

参考文献2

二级参考文献11

共引文献28

同被引文献15

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部