The Experts below are selected from a list of 62202 Experts worldwide ranked by ideXlab platform

Ju An Wang - One of the best experts on this subject based on the ideXlab platform.

  • Measuring and ranking attacks based on Vulnerability analysis
    Information Systems and e-Business Management, 2012
    Co-Authors: Ju An Wang, Hao Wang, Linfeng Zhou
    Abstract:

    As the number of software vulnerabilities increases, the research on software vulnerabilities becomes a focusing point in information security. A Vulnerability could be exploited to attack the information asset with the weakness related to the Vulnerability. However, multiple attacks may target one software product at the same time, and it is necessary to rank and prioritize those attacks in order to establish a better defense. This paper proposes a similarity measurement to compare and categorize vulnerabilities, and a set of security metrics to rank attacks based on Vulnerability analysis. The Vulnerability information is retrieved from a Vulnerability Management ontology integrating commonly used standards like CVE ( http://www.cve.mitre.org/ ), CWE ( http://www.cwe.mitre.org/ ), CVSS ( http://www.first.org/cvss/ ), and CAPEC ( http://www.capec.mitre.org/ ). This approach can be used in many areas of Vulnerability Management to secure information systems and e-business, such as Vulnerability classification, mitigation and patching, threat detection and attack prevention.

  • HICSS - Measuring Similarity for Security Vulnerabilities
    2010 43rd Hawaii International Conference on System Sciences, 2010
    Co-Authors: Ju An Wang, Linfeng Zhou, Minzhe Guo, Hao Wang, Jairo Camargo
    Abstract:

    As the number of software vulnerabilities increases year by year, software Vulnerability becomes a focusing point in information security. This paper proposes a Vulnerability similarity measurement to compare different vulnerabilities according to a set of criteria. Our approach is based on the structural hierarchy of vulnerabilities, and the similarity is defined using established mathematical models. The National Vulnerability Database and the Ontology of Vulnerability Management provide the information necessary for the similarity calculation. The similarity measurement can be used in many areas of Vulnerability Management, such as Vulnerability classification, mitigation, and patching.

  • security data mining in an ontology for Vulnerability Management
    International Joint Conferences on Bioinformatics Systems Biology and Intelligent Computing, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    Information security is such a complex topic that the sheer scope and volume of available security data overwhelms security professionals and managers alike. This paper discusses the rationale of applying semantic technology to information security with a focus on software Vulnerability Management. With semantic technologies, we can describe the pattern of external threats and internal vulnerabilities formally and precisely. Based on this, we can make inference and make high-level decisions accordingly. We have constructed an ontology for security vulnerabilities, which defines the key concepts in Vulnerability Management and their relationships. We introduce the design and reasoning within the ontology with examples in Vulnerability analysis and assessment. The result of this paper provides a promising pathway to making security automation successful through semantic technologies.

  • ovm an ontology for Vulnerability Management
    Cyber Security and Information Intelligence Research Workshop, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    In order to reach the goals of the Information Security Automation Program (ISAP) [1], we propose an ontological approach to capturing and utilizing the fundamental concepts in information security and their relationship, retrieving Vulnerability data and reasoning about the cause and impact of vulnerabilities. Our ontology for Vulnerability Management (OVM) has been populated with all vulnerabilities in NVD [2] with additional inference rules, knowledge representation, and data-mining mechanisms. With the seamless integration of common vulnerabilities and their related concepts such as attacks and countermeasures, OVM provides a promising pathway to making ISAP successful.

  • IJCBS - Security Data Mining in an Ontology for Vulnerability Management
    2009 International Joint Conference on Bioinformatics Systems Biology and Intelligent Computing, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    Information security is such a complex topic that the sheer scope and volume of available security data overwhelms security professionals and managers alike. This paper discusses the rationale of applying semantic technology to information security with a focus on software Vulnerability Management. With semantic technologies, we can describe the pattern of external threats and internal vulnerabilities formally and precisely. Based on this, we can make inference and make high-level decisions accordingly. We have constructed an ontology for security vulnerabilities, which defines the key concepts in Vulnerability Management and their relationships. We introduce the design and reasoning within the ontology with examples in Vulnerability analysis and assessment. The result of this paper provides a promising pathway to making security automation successful through semantic technologies.

Minzhe Guo - One of the best experts on this subject based on the ideXlab platform.

  • HICSS - Measuring Similarity for Security Vulnerabilities
    2010 43rd Hawaii International Conference on System Sciences, 2010
    Co-Authors: Ju An Wang, Linfeng Zhou, Minzhe Guo, Hao Wang, Jairo Camargo
    Abstract:

    As the number of software vulnerabilities increases year by year, software Vulnerability becomes a focusing point in information security. This paper proposes a Vulnerability similarity measurement to compare different vulnerabilities according to a set of criteria. Our approach is based on the structural hierarchy of vulnerabilities, and the similarity is defined using established mathematical models. The National Vulnerability Database and the Ontology of Vulnerability Management provide the information necessary for the similarity calculation. The similarity measurement can be used in many areas of Vulnerability Management, such as Vulnerability classification, mitigation, and patching.

  • security data mining in an ontology for Vulnerability Management
    International Joint Conferences on Bioinformatics Systems Biology and Intelligent Computing, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    Information security is such a complex topic that the sheer scope and volume of available security data overwhelms security professionals and managers alike. This paper discusses the rationale of applying semantic technology to information security with a focus on software Vulnerability Management. With semantic technologies, we can describe the pattern of external threats and internal vulnerabilities formally and precisely. Based on this, we can make inference and make high-level decisions accordingly. We have constructed an ontology for security vulnerabilities, which defines the key concepts in Vulnerability Management and their relationships. We introduce the design and reasoning within the ontology with examples in Vulnerability analysis and assessment. The result of this paper provides a promising pathway to making security automation successful through semantic technologies.

  • ovm an ontology for Vulnerability Management
    Cyber Security and Information Intelligence Research Workshop, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    In order to reach the goals of the Information Security Automation Program (ISAP) [1], we propose an ontological approach to capturing and utilizing the fundamental concepts in information security and their relationship, retrieving Vulnerability data and reasoning about the cause and impact of vulnerabilities. Our ontology for Vulnerability Management (OVM) has been populated with all vulnerabilities in NVD [2] with additional inference rules, knowledge representation, and data-mining mechanisms. With the seamless integration of common vulnerabilities and their related concepts such as attacks and countermeasures, OVM provides a promising pathway to making ISAP successful.

  • IJCBS - Security Data Mining in an Ontology for Vulnerability Management
    2009 International Joint Conference on Bioinformatics Systems Biology and Intelligent Computing, 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    Information security is such a complex topic that the sheer scope and volume of available security data overwhelms security professionals and managers alike. This paper discusses the rationale of applying semantic technology to information security with a focus on software Vulnerability Management. With semantic technologies, we can describe the pattern of external threats and internal vulnerabilities formally and precisely. Based on this, we can make inference and make high-level decisions accordingly. We have constructed an ontology for security vulnerabilities, which defines the key concepts in Vulnerability Management and their relationships. We introduce the design and reasoning within the ontology with examples in Vulnerability analysis and assessment. The result of this paper provides a promising pathway to making security automation successful through semantic technologies.

  • CSIIRW - OVM: an ontology for Vulnerability Management
    Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research Cyber Security and Information Intelligence Challenges , 2009
    Co-Authors: Ju An Wang, Minzhe Guo
    Abstract:

    In order to reach the goals of the Information Security Automation Program (ISAP) [1], we propose an ontological approach to capturing and utilizing the fundamental concepts in information security and their relationship, retrieving Vulnerability data and reasoning about the cause and impact of vulnerabilities. Our ontology for Vulnerability Management (OVM) has been populated with all vulnerabilities in NVD [2] with additional inference rules, knowledge representation, and data-mining mechanisms. With the seamless integration of common vulnerabilities and their related concepts such as attacks and countermeasures, OVM provides a promising pathway to making ISAP successful.

Franck Marle - One of the best experts on this subject based on the ideXlab platform.

  • A systems thinking approach for project Vulnerability Management
    Kybernetes, 2012
    Co-Authors: Ludovic-alexandre Vidal, Franck Marle
    Abstract:

    Purpose – The purpose of this paper is to develop the concept of project Vulnerability in order to focus on the weaknesses of a project system, instead of focusing on risk evaluation only. The paper concentrates on a systems thinking‐based view to highlight the potentially endangered elements of a project, including its outcomes.Design/methodology/approach – The paper gives a broad state of the art in many scientific domains; a definition of project Vulnerability; a description of a project Vulnerability Management process, including identification, analysis and response plan; and a test on an industrial case study.Findings – The author's project Vulnerability Management process permits one to concentrate directly on the existing weaknesses of a project system, which may create potential damages regarding the project values creation. By focusing on this system, response plans may be more adapted to the existing short comings of the project.Research limitations/implications – Some aspects of the vulnerabil...

  • A systems thinking approach for project Vulnerability Management
    Kybernetes, 2012
    Co-Authors: Ludovic-alexandre Vidal, Franck Marle
    Abstract:

    Purpose: This papers aims at developing the concept of project Vulnerability in order to focus on the weaknesses of a project system, instead of focusing on risk evaluation only. We then aim at concentrating on a systems thinking based view to highlight the potentially endangered elements of a project, including its outcomes. Design/methodology/approach: •A broad state of the art in many scientific domains. •A definition of project Vulnerability. •A description of a project Vulnerability Management process, including identification, analysis and response plan. •A test on an industrial case study Findings: Our project Vulnerability Management process permits to concentrate directly on the existing weaknesses of a project system which may create potential damages regarding the project values creation. By focusing on this system, response plans may be more adapted to the existing lacks of the project. Research limitations/implications: Some aspects of the Vulnerability definition should be refined, like the concepts of susceptibility or cruciality. Other promising works may focus on the evaluation of the non-resistance and resilience, notably thanks to the introduction of interdependences which exist in complex projects. Practical implications: A case study was done on a decision support system (called FabACT) developed at Hôpital Européen Georges Pompidou Pharmacy department. The aim of this project was to achieve a better balance between the workload and the efficiency of the compounding unit. Originality/value: This article presents an innovative way to analyse a project’s Vulnerability by focusing on its existing weaknesses using a systems thinking-based approach.

Susan Snedakar - One of the best experts on this subject based on the ideXlab platform.

  • Vulnerability Management Tools
    The Best Damn IT Security Management Book Period, 2007
    Co-Authors: Susan Snedakar
    Abstract:

    This chapter discusses what an ideal Vulnerability tool features. It discusses some of the Vulnerability Management tools but provides no suggestions regarding the pros and cons of the tools because there is no tool that fits all the requirements of an organization. It provides some of the pros and cons of leveraging an outsourcer to manage parts of a Vulnerability Management program. It is conceivable, and many organizations do it, but it is imperative to put in place some serious guidelines and detailed service-level agreements beforehand to ensure that no one becomes disappointed with the delivery of the service. Ideally, the tool's asset Management, Vulnerability Management, and patch Management capabilities work well together, for three reasons. First, asset Management represents the foundation of a Vulnerability Management program. Without a complete and up-to-date asset inventory, a Vulnerability Management program will be only marginally effective. Therefore, it is critical that the tools leverage this repository for the list of assets represented within the environment. Second, it would be good if Vulnerability Management tools and auxiliary tools could communicate with one another. And third, patching and configuration Management are key elements of the remediation process and of the Vulnerability Management plan. Understanding which systems are patched, along with their respective configurations, is one thing, but having this information populated within the asset database and being able to extract this data and use it to make informed security decisions is a capability which all security practitioners wish they had.

  • Chapter 7 – Vulnerability Management
    The Best Damn IT Security Management Book Period, 2007
    Co-Authors: Susan Snedakar
    Abstract:

    Publisher Summary This chapter discusses the elements and aspects of an effective Vulnerability Management program. It refers to setting goals for the program and the need to get buy-in from senior Management. It highlights the importance of communication and the inclusion of all parties (lines of business, IT, and security) to the success of a program. Vulnerability Management is composed of six stages that include identification, assessment, remediation, reporting, improving, and monitoring. The chapter explains the intricacies of each stage and suggests best practices for each. It briefly explains governance and its impact on a Vulnerability Management program, as well as the roles which regulations play in elevating IT governance within corporate America. It shows how to measure a Vulnerability Management program and provides examples of how to do this. It discusses the more effective method of measuring the maturity of a Vulnerability Management program, and a method for determining the current state of a program. Vulnerability Management is best defined as the overall process of managing the risk presented to an enterprise due to vulnerabilities, whether they are software or hardware related. Vulnerability Management ties directly into Vulnerability discovery and Vulnerability assessment in many ways, and depends greatly on the patch Management process as well.

  • Tying It All Together
    The Best Damn IT Security Management Book Period, 2007
    Co-Authors: Susan Snedakar
    Abstract:

    This chapter ties Vulnerability Management procedures together nicely and provides a concise guide. Successfully creating a Vulnerability Management program that becomes easier to administer day by day involves eight steps: knowing the assets, categorizing the assets, creating a baseline scan of all assets, performing a penetration test on certain assets, remediating vulnerabilities and risk, creating a Vulnerability assessment (VA) schedule, creating a patch and change Management process, monitoring for new risks to assets, and washing, rinsing, and repeating. The typical network is a diverse environment, so manually monitoring all of these resources can be time consuming. As such, some organizations go so far as to hire security analysts whose job is to do nothing but monitor for new threats. Luckily, some vendors have stepped up to the plate and created solutions that are designed to help managers battle the massive amounts of information this work generates so they can concentrate only on the issues that matter to the organization.

  • Vulnerability and Configuration Management
    The Best Damn IT Security Management Book Period, 2007
    Co-Authors: Susan Snedakar
    Abstract:

    This chapter covers the process of remediating vulnerabilities. Dealing effectively with vulnerabilities in today's networks includes not only managing and dealing with the Vulnerability process itself but also integrating the previous approach toward Vulnerability assessment (leveraging scanners to discovery vulnerabilities) into the correlative frameworks and processes of patch Management, configuration Management, and change control. It focuses on these frameworks and processes. Understanding what these processes are, their similarities and differences, and how they integrate with the Vulnerability life cycle is essential to putting an effective Vulnerability Management program together. The most crucial components of a Vulnerability Management framework lie in the establishment of a patch Management program. Patches can be software or hardware related, and the results of one patch can often affect the operation of both the primary and secondary functions of another patch. The principles behind configuration Management are very similar to those of patch Management. The rule of document, test, deploy, and test again are as true here as they are with patch Management.

Brad Hibbert - One of the best experts on this subject based on the ideXlab platform.

  • Vulnerability Management Development
    Asset Attack Vectors, 2018
    Co-Authors: Morey J. Haber, Brad Hibbert
    Abstract:

    A well-planned Vulnerability Management program that aligns with the overall organization’s risk Management program can assist in this process by reducing the overall attack surface by:

  • Vulnerability Management Deployment
    Asset Attack Vectors, 2018
    Co-Authors: Morey J. Haber, Brad Hibbert
    Abstract:

    Now that the Vulnerability process and associated technologies have been thoroughly tested and validated in a lab and/or pilot deployment, it’s time to roll it out to the production environment where it will be run on an ongoing basis. It is recommended that enterprise deployment of a Vulnerability Management solution and supporting processes be implemented in a phased approach. This controlled approach enables the deployment team to uncover and address challenges using a controlled and manageable approach. Figure 15-1 highlights the tasks for a successful deployment.

  • Vulnerability Management Architecture
    Asset Attack Vectors, 2018
    Co-Authors: Morey J. Haber, Brad Hibbert
    Abstract:

    Once a vendor has been selected for Vulnerability Management, the process of an actual implementation will vary greatly from one vendor to another. The simple question is why? Each of the leading vendors has taken a different technology approach to instrumenting Vulnerability Management at the console or Management layer but is actually very similar at the scanning layer. This is why you hear security professionals state, “a network scanner is a network scanner” or that “Vulnerability assessment is a commodity.” The truth is that scanners are definitely a commodity but how the data is aggregated, scans are performed, and the type of reports available are what differentiate each of the vendors. They all have false positives; they all have false negatives; some are faster at scanning one type of asset over another; and in the end, it’s the people and support that will make the difference with results and integration from the Management console. Some security professionals will have a favorite solution but the deployment of each, from a Management console perspective – not scanner, will vary due to on-premise technology, hosted solution, peer-to-peer databases, air gapped networks, appliances, agents, etc. All deployments need the traits discussed in this book, but the architectural topology from one vendor to another will be different. Some will connect to the cloud, some will use a spoke-and-wheel tiered hierarchy, and others peer to peer. Which architecture fits your network best is a decision only you can make. Consider the following:

  • Vulnerability Management Design
    Asset Attack Vectors, 2018
    Co-Authors: Morey J. Haber, Brad Hibbert
    Abstract:

    A key requirement for any Security Officer is reducing the risks of a cyber attack by finding and closing off holes in the IT infrastructure, and this is exactly what a sound Vulnerability Management (VM) program should do. An effective VM program should be designed to ensure that the people, processes, policies, and selected technologies work together to proactively protect, shield, and defend the enterprise from cyber threats. As threats cannot be completely eliminated, and as the Security Officer does not have unlimited resources, his/her job to ensure the associated security and compliance risk is well communicated, understand, and falls within an organization’s tolerance levels.

  • The Vulnerability Management Program
    Asset Attack Vectors, 2018
    Co-Authors: Morey J. Haber, Brad Hibbert
    Abstract:

    With the recent spate of high-profile data breaches, security-conscious organizations realize that their financial viability and business continuity depend on effective IT security risk Management. Given the potential fallout of a breach, many organizations rely on Vulnerability and compliance Management initiatives to keep their critical information secure, protect sensitive systems, and demonstrate compliance with regulatory requirements. These efforts are further complicated by burgeoning new security exposures introduced by a proliferation of applications, employee-owned devices, mobile computing, social networks, and other expanding attack surfaces. As well, critical compliance regulations, such as PCI, HIPAA, and Sarbanes-Oxley, also mandate specific security controls pertaining to Vulnerability Management. Unfortunately, there’s no way around the harsh reality that noncompliance results in penalties, lost business, and other indirect costs. Additionally, aligning internal security processes with regulations and providing meaningful reports to Management and auditors are notoriously time-consuming and costly exercises.