Abstract
Evaluation of security policies, specifically access control policies, plays an important part in securing the network by ensuring that policies are correct and consistent. Quality of protection (QoP) of a policy depends on a number of factors. Thus it is desirable to have one unified score based on these factors to judge the quality of the policy and to compare policies. In this context, we present our method of calculating a metric based on a number of factors like the vulnerabilities present in the system, vulnerability history of the services and their exposure to the network, and traffic patterns. We measure the existing vulnerability by combining the severity scores of the vulnerabilities present in the system. We mine the National Vulnerability Database, NVD, provided by NIST, to find the vulnerability history of the services running on the system, and from the frequency and severity of the past vulnerabilities, we measure the historical vulnerability of the policy using a decay factor. In both cases, we take into account the exposure of the service to the network and the traffic volume handled by the service. Finally, we combine these scores into one unified score - the Policy Security Score.
| Original language | English |
|---|---|
| Title of host publication | Proceedings of the 2nd ACM Workshop on Quality of Protection, QoP'06. Co-located with the 13th ACM Conference on Computer and Communications Security, CCS'06 |
| Pages | 49-52 |
| Number of pages | 4 |
| DOIs | |
| State | Published - 2006 |
| Externally published | Yes |
| Event | 2nd ACM Workshop on Quality of Protection, QoP'06. Co-located with the 13th ACM Conference on Computer and Communications Security, CCS'06 - Alexandria, VA, United States Duration: 30 Oct 2006 → 30 Oct 2006 |
Publication series
| Name | Proceedings of the 2nd ACM Workshop on Quality of Protection, QoP'06. Co-located with the 13th ACM Conference on Computer and Communications Security, CCS'06 |
|---|
Conference
| Conference | 2nd ACM Workshop on Quality of Protection, QoP'06. Co-located with the 13th ACM Conference on Computer and Communications Security, CCS'06 |
|---|---|
| Country/Territory | United States |
| City | Alexandria, VA |
| Period | 30/10/06 → 30/10/06 |
UN SDGs
This output contributes to the following UN Sustainable Development Goals (SDGs)
-
SDG 1 No Poverty
Keywords
- Evaluation
- Metric
- Policy
- Security
ASJC Scopus subject areas
- Computer Networks and Communications
- Software
Fingerprint
Dive into the research topics of 'Vulnerability analysis For evaluating quality of protection of security policies'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver