Optimizing The Roi Of Cyber Risk Mitigation

CNSM 2016: Proceedings of the 12th Conference on International Conference on Network and Service Management(2016)

引用 2|浏览25
暂无评分
摘要
In this paper, we present a security analytics framework that augments host compliance reports with network configuration to assess the risk globally and devise cost-effective mitigation plans. We define metrics to measure the global enterprise risk based on network assets' vulnerabilities, their inter-dependencies, and network configurations. Our framework takes the decision burden away from administrators by automatically recommending cost-effective mitigation actions that achieve the expected return on investment (RoI). We use XCCDF, a language defined as part of the Security Content Automation Protocol (SCAP), to communicate the compliance benchmarking and scoring reports. In addition, we utilize the basic metrics defined in the standard vulnerability scoring systems, such as CVSS, to accurately assess the global risk. We formalize our proposed mitigation planning solution as a constraints satisfaction problem and we solve it using the Z3 SMT solver.
更多
查看译文
关键词
RoI,cyber risk mitigation,security analytics framework,host compliance reports,risk assessment,global enterprise risk,network asset vulnerabilities,return on investment,XCCDF,Security Content Automation Protocol,SCAP,vulnerability scoring systems,mitigation planning solution,constraint satisfaction problem,Z3 SMT solver
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要