DocumentCode
3548169
Title
Quantitative assessment of software vulnerabilities based on economic-driven security metrics
Author
Ghani, Hamza ; Luna, Jesus ; Suri, Neeraj
Author_Institution
Tech. Univ. Darmstadt, Darmstadt, Germany
fYear
2013
fDate
23-25 Oct. 2013
Firstpage
1
Lastpage
8
Abstract
Vulnerability exploits cost organizations large amounts of resources, mainly due to disruption of ICT services, and thus loss of confidentiality, integrity and availability. As security managers in the industry usually have to operate with limited budgets allocated to information security, they need to prioritize their investment efforts regarding the response mechanisms to the existing vulnerabilities. The utilization of quantitative security vulnerability assessment methods enables efficient prioritization of security efforts and investments to mitigate the discovered vulnerabilities and thus an opportunity to lower expected losses. State of the art approaches for vulnerability assessment such as the Common Vulnerability Scoring System (CVSS), which is the de facto standard quantifying the severity of vulnerabilities, do not consider the economic impact in case of a vulnerability exploit. To this end, our paper targets the quantitative understanding of vulnerability severity taking into account the potential economic damage a successful vulnerability exploit can cause. We propose a novel approach for a systematic consideration of the relevant cost units (associated costs) for the economic damage estimation of vulnerability exploits. Our approach utilizes Multiple Criteria Decision Analysis (MCDA) methods to perform a prioritization of the existing vulnerabilities within the target system. The evaluation results show the potential cost savings w.r.t. the mitigation costs using our approach. Our method supports managers and decision makers in the process of prioritizing security investments to mitigate the discovered vulnerabilities.
Keywords
security of data; software metrics; CVSS; ICT services; MCDA methods; common vulnerability scoring system; economic-driven security metrics; information security; multiple criteria decision analysis method; quantitative security vulnerability assessment methods; software vulnerabilities; Forensics; IP networks; Measurement; Personnel; Security; CVSS; MCDA; economic-driven security metrics; security quantification; vulnerability assessment;
fLanguage
English
Publisher
ieee
Conference_Titel
Risks and Security of Internet and Systems (CRiSIS), 2013 International Conference on
Conference_Location
La Rochelle
Type
conf
DOI
10.1109/CRiSIS.2013.6766361
Filename
6766361
Link To Document