Quantifying security risk level from CVSS estimates of frequency and impact

被引:62
作者
Houmb, Siv Hilde [1 ]
Franqueira, Virginia N. L. [2 ]
Engum, Erlend A. [3 ]
机构
[1] Tele Nor R&I, Connected Objects Lab, Serv Platforms Grp, N-7004 Trondheim, Norway
[2] Univ Twente, CTIT, Informat Syst Grp, NL-7522 NB Enschede, Netherlands
[3] Natl Oilwell Varco, N-4069 Stavanger, Norway
关键词
Quantitative risk analysis; Security risks; Risk estimation; Common Vulnerability Scoring System (CVSS); Dependable systems; Remote operation; EXPERT JUDGMENT;
D O I
10.1016/j.jss.2009.08.023
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Modern society relies on and profits from well-balanced computerized systems. Each of these systems has a core mission such as the correct and safe operation of safety critical systems or innovative and effective operation of e-commerce systems. It might be said that the success of these systems depends on their mission. Although the concept of "well-balanced" has a slightly different meaning for each of these two categories of systems, both have to meet customer needs, deliver capabilities and functions according to expectations and generate revenue to sustain today's highly competitive market. Tighter financial constraints are forcing safety critical systems away from dedicated and expensive communication regimes, such as the ownership and operation of dedicated communication links, towards reliance on third parties and standardized means of communication. As a consequence, knowledge about their internal structures and operations is more widely and publicly available and this can make them more prone to security attacks. These systems are, therefore, moving towards a remotely exploitable environment and the risks associated with this must be controlled. Risk management is a good tool for controlling risk but it has the inherent challenge of quantitatively estimating frequency and impact in an accurate and trustworthy way. Quantifying the frequency and impact of potential security threats requires experience-based data which is limited and rarely reusable because it involves company confidential data. Therefore, there is a need for publicly available data sources that can be used in risk estimation. This paper presents a risk estimation model that makes use of one such data source, the Common Vulnerability Scoring System (CVSS). The CVSS Risk Level Estimation Model estimates a security risk level from vulnerability information as a combination of frequency and impact estimates derived from the CVSS. It is implemented as a Bayesian Belief Network (BBN) topology, which allows not only the use of CVSS-based estimates but also the combination of disparate information sources and, thus, provides the ability to use whatever risk information that is available. The model is demonstrated using a safety- and mission-critical system for drilling operational support, the Measurement and Logging While Drilling (M/LWD) system. (C) 2009 Elsevier Inc. All rights reserved.
引用
收藏
页码:1622 / 1634
页数:13
相关论文
共 44 条
[1]  
Alberts ChristopherJ., 1999, OPERATIONALLY CRITIC
[2]  
ALDRED W, 2005, SCHLUMBERGER OILFIEL, V17, P42
[3]  
[Anonymous], 2007, 1 FORUM INCIDENT RES
[4]  
[Anonymous], 1991, EXPERTS UNCERTAINTY
[5]  
[Anonymous], NATL VULNERABILITY D
[6]  
[Anonymous], 270022005 ISOIEC
[7]  
[Anonymous], 1996, An introduction to Bayesian networks
[8]  
[Anonymous], 270012005 ISOIEC
[9]  
[Anonymous], 1992, Dependability: Basic Concepts and Terminology
[10]  
Australian/New Zealand Standards, 2004, 43602004 ASNZS