The Experts below are selected from a list of 16110 Experts worldwide ranked by ideXlab platform

Taylor J Canann - One of the best experts on this subject based on the ideXlab platform.

  • toward a theory of Vulnerability disclosure policy a hacker s game
    Decision and Game Theory for Security, 2019
    Co-Authors: Taylor J Canann
    Abstract:

    A game between software vendors, heterogeneous software users, and a hacker is introduced in which software vendors attempt to protect software users by releasing updates, i.e. disclosing a Vulnerability, and the hacker is attempting to exploit vulnerabilities in the software package to attack the software users. The software users must determine whether the protection offered by the update outweighs the cost of installing the update. Following the model is a description of why the disclosure of vulnerabilities can only be an optimal policy when the cost to the hacker of searching for a Zero-Day Vulnerability is small. The model is also extended to discuss Microsoft’s new “extended support” disclosure policy.

  • GameSec - Toward a Theory of Vulnerability Disclosure Policy: A Hacker's Game.
    Lecture Notes in Computer Science, 2019
    Co-Authors: Taylor J Canann
    Abstract:

    A game between software vendors, heterogeneous software users, and a hacker is introduced in which software vendors attempt to protect software users by releasing updates, i.e. disclosing a Vulnerability, and the hacker is attempting to exploit vulnerabilities in the software package to attack the software users. The software users must determine whether the protection offered by the update outweighs the cost of installing the update. Following the model is a description of why the disclosure of vulnerabilities can only be an optimal policy when the cost to the hacker of searching for a Zero-Day Vulnerability is small. The model is also extended to discuss Microsoft’s new “extended support” disclosure policy.

Mathias Ekstedt - One of the best experts on this subject based on the ideXlab platform.

  • time between Vulnerability disclosures a measure of software product Vulnerability
    Computers & Security, 2016
    Co-Authors: Pontus Johnson, Dan Gorton, Robert Lagerström, Mathias Ekstedt
    Abstract:

    Time between Vulnerability disclosure (TBVD) for individual analysts is proposed as a meaningful measure of the likelihood of finding a Zero-Day Vulnerability within a given timeframe. Based on pub ...

  • HICSS - Effort Estimates for Vulnerability Discovery Projects
    2012 45th Hawaii International Conference on System Sciences, 2012
    Co-Authors: Teodor Sommestad, Hannes Holm, Mathias Ekstedt
    Abstract:

    Security vulnerabilities continue to be an issue in the software field and new severe vulnerabilities are discovered in software products each month. This paper analyzes estimates from domain experts on the amount of effort required for a penetration tester to find a Zero-Day Vulnerability in a software product. Estimates are developed using Cooke's classical method for 16 types of Vulnerability discovery projects -- each corresponding to a configuration of four security measures. The estimates indicate that, regardless of project type, two weeks of testing are enough to discover a software Vulnerability of high severity with fifty percent chance. In some project types an eight-to-five-week is enough to find a Zero-Day Vulnerability with 95 percent probability. While all studied measures increase the effort required for the penetration tester none of them have a striking impact on the effort required to find a Vulnerability.

Yuanbo Guo - One of the best experts on this subject based on the ideXlab platform.

  • ICAIS (4) - Zero-Day Vulnerability Risk Assessment and Attack Path Analysis Using Security Metric
    Lecture Notes in Computer Science, 2019
    Co-Authors: Yuanbo Guo
    Abstract:

    Zero-Day Vulnerability has been considered one of the most serious threats to network security at present. Current researches on Zero-Day Vulnerability risk assessment are mainly focused on the number of necessary Zero-Day vulnerabilities for attack to exploit to reach the target. However, in practice, it is difficult to realize risk assessment of single Zero-Day Vulnerability by existing methods. In this paper, a Zero-Day Vulnerability and attack path risk assessment method is proposed for internal network. Four kinds of security metrics and a Zero-Day Vulnerability discovery and Zero-Day attack graph generation algorithm are designed. By contrasting the preconditions with postconditions of known vulnerabilities, attack complexity and impact of Zero-Day vulnerabilities in various contexts are analyzed. Experimental results show that the proposed method can quantitatively assess risk of single Zero-Day Vulnerability and attack path from multiple dimensionalities.

Elena Doynikova - One of the best experts on this subject based on the ideXlab platform.

  • COMPREHENSIVE MULTILEVEL SECURITY RISK ASSESSMENT OF DISTRIBUTED INFORMATION SYSTEMS
    International Journal of Computing, 2014
    Co-Authors: Igor Kotenko, Elena Doynikova
    Abstract:

    The paper suggests the multilevel approach to the risk assessment that is based on the system of security metrics and techniques for their calculation. Proposed techniques are based on attack graphs and service dependencies. They allow evaluating security of network topologies, malefactors and attack characteristics, and integral security properties and characteristics calculated on the basis of the cost-benefit and Zero-Day Vulnerability analysis. Classification of these characteristics and separation of the security information on static, dynamic and historical allows defining different assessment levels. The paper considers the main issues and recommendations for using the risk assessment techniques based on the suggested approach.

  • IDAACS - Security metrics for risk assessment of distributed information systems
    2013 IEEE 7th International Conference on Intelligent Data Acquisition and Advanced Computing Systems (IDAACS), 2013
    Co-Authors: Igor Kotenko, Elena Doynikova
    Abstract:

    The paper considers the main issues and recommendations for using the risk assessment techniques based on the analysis of static, dynamic and historical security information. The system of security metrics and techniques for their calculation are suggested. Proposed techniques are based on attack graphs and service dependencies. They allow evaluating security of network topologies, malefactors and attack characteristics, and integral security properties and characteristics calculated on the basis of the cost-benefit and Zero-Day Vulnerability analysis. The approach is intended to be implemented in the framework of the FP7 EU MASSIF project.

  • IDAACS - Security metrics for risk assessment of distributed information systems
    2013 IEEE 7th International Conference on Intelligent Data Acquisition and Advanced Computing Systems (IDAACS), 2013
    Co-Authors: Igor Kotenko, Elena Doynikova
    Abstract:

    The paper considers the main issues and recommendations for using the risk assessment techniques based on the analysis of static, dynamic and historical security information. The system of security metrics and techniques for their calculation are suggested. Proposed techniques are based on attack graphs and service dependencies. They allow evaluating security of network topologies, malefactors and attack characteristics, and integral security properties and characteristics calculated on the basis of the cost-benefit and Zero-Day Vulnerability analysis. The approach is intended to be implemented in the framework of the FP7 EU MASSIF project.

Qublai Khan Ali Mirza - One of the best experts on this subject based on the ideXlab platform.

  • An Intelligent and Time-Efficient DDoS Identification Framework for Real-Time Enterprise Networks: SAD-F: Spark Based Anomaly Detection Framework
    IEEE Access, 2020
    Co-Authors: Awais Ahmed, Sufian Hameed, Muhammad Rafi, Qublai Khan Ali Mirza
    Abstract:

    Enterprise networks face a large number of threats that are managed and mitigated with a combination of proprietary and third-party security tools and services. However, the techniques and principles employed by the said tools, processes, and services are quite conventional. They lack the rapid evolution, as required to protect against modern, state-of-the-art threats faced, specifically, against distributed denial of service (DDoS) attacks. The lack of efficiency of a network is directly proportional to the number of applications and services it hosts, mainly to protect against external and internal threats. Moreover, the effectiveness of such security mechanisms relies on their independent and proactive approach, which is useful for known malware and their attack vectors, but become obsolete when there is a new malware or Zero-Day Vulnerability is exploits. This paper presents an intelligent, highly responsive, and scalable security framework for enterprise networks. The proposed framework incorporates Apache Spark Framework for security analytics. It accurately identifies anomalies related to DDoS attacks from real-time network traffic by using customized machine learning algorithms, meticulously trained against selected feature-set. Encouraging results are obtained when tested against different scenarios and bench-marked with the results achieved by related studies in similar scenarios.