• DocumentCode
    1762581
  • Title

    k-Zero Day Safety: A Network Security Metric for Measuring the Risk of Unknown Vulnerabilities

  • Author

    Lingyu Wang ; Jajodia, Sushil ; Singhal, Achintya ; Pengsu Cheng ; Noel, S.

  • Author_Institution
    Concordia Inst. for Inf. Syst. Eng. (CIISE), Concordia Univ., Montreal, QC, Canada
  • Volume
    11
  • Issue
    1
  • fYear
    2014
  • fDate
    Jan.-Feb. 2014
  • Firstpage
    30
  • Lastpage
    44
  • Abstract
    By enabling a direct comparison of different security solutions with respect to their relative effectiveness, a network security metric may provide quantifiable evidences to assist security practitioners in securing computer networks. However, research on security metrics has been hindered by difficulties in handling zero-day attacks exploiting unknown vulnerabilities. In fact, the security risk of unknown vulnerabilities has been considered as something unmeasurable due to the less predictable nature of software flaws. This causes a major difficulty to security metrics, because a more secure configuration would be of little value if it were equally susceptible to zero-day attacks. In this paper, we propose a novel security metric, k-zero day safety, to address this issue. Instead of attempting to rank unknown vulnerabilities, our metric counts how many such vulnerabilities would be required for compromising network assets; a larger count implies more security because the likelihood of having more unknown vulnerabilities available, applicable, and exploitable all at the same time will be significantly lower. We formally define the metric, analyze the complexity of computing the metric, devise heuristic algorithms for intractable cases, and finally demonstrate through case studies that applying the metric to existing network security practices may generate actionable knowledge.
  • Keywords
    computer network security; computational complexity; heuristic algorithms; k zero day safety; network security metric; software flaws; Security metrics; attack graph; network hardening; network security;
  • fLanguage
    English
  • Journal_Title
    Dependable and Secure Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1545-5971
  • Type

    jour

  • DOI
    10.1109/TDSC.2013.24
  • Filename
    6529081