• DocumentCode
    729401
  • Title

    Exploitability analysis using predictive cybersecurity framework

  • Author

    Abraham, Subil ; Nair, Suku

  • Author_Institution
    IBM Global Solution Center, Coppell, TX, USA
  • fYear
    2015
  • fDate
    24-26 June 2015
  • Firstpage
    317
  • Lastpage
    323
  • Abstract
    Managing Security is a complex process and existing research in the field of cybersecurity metrics provide limited insight into understanding the impact attacks have on the overall security goals of an enterprise. We need a new generation of metrics that can enable enterprises to react even faster in order to properly protect mission-critical systems in the midst of both undiscovered and disclosed vulnerabilities. In this paper, we propose a practical and predictive security model for exploitability analysis in a networking environment using stochastic modeling. Our model is built upon the trusted CVSS Exploitability framework and we analyze how the atomic attributes namely Access Complexity, Access Vector and Authentication that make up the exploitability score evolve over a specific time period. We formally define a nonhomogeneous Markov model which incorporates time dependent covariates, namely the vulnerability age and the vulnerability discovery rate. The daily transition-probability matrices in our study are estimated using a combination of Frei´s model & Alhazmi Malaiya´s Logistic model. An exploitability analysis is conducted to show the feasibility and effectiveness of our proposed approach. Our approach enables enterprises to apply analytics using a predictive cyber security model to improve decision making and reduce risk.
  • Keywords
    Markov processes; authorisation; decision making; risk management; access complexity; access vector; authentication; daily transition-probability matrices; decision making; exploitability analysis; nonhomogeneous Markov model; predictive cybersecurity framework; risk reduction; trusted CVSS exploitability framework; vulnerability age; vulnerability discovery rate; Analytical models; Computer security; Markov processes; Measurement; Predictive models; Attack Graph; CVSS; Markov Model; Security Metrics; Vulnerability Discovery Model; Vulnerability Lifecyle Model;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Cybernetics (CYBCONF), 2015 IEEE 2nd International Conference on
  • Conference_Location
    Gdynia
  • Print_ISBN
    978-1-4799-8320-9
  • Type

    conf

  • DOI
    10.1109/CYBConf.2015.7175953
  • Filename
    7175953