The new frontiers of digital attack and compromise have led to the evolution of security at an organisational level. Recent security regulations and directives require the implementation of specific security measures in the organisations they address. Consequently, organisations need to be compliant with those measures. At the same time, however, the phenomenon of non-compliance is realistic, a scenario in which some measures are ultimately not implemented due to various reasons ranging from ignorance to financial hardship. Of course, this could lead to security flaws. This paper provides a method to carry out a security weakness assessment in an automated manner, starting from the security measures whose implementation is neglected. Such measures are first correlated using semantic similarity to known attack patterns. Then, the correct associations between measures and attack patterns are chosen using two innovative algorithms running on top of the calculated semantic similarity values. The method is demonstrated in the European NIS 2 Directive and the CAPEC catalogue.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Compliance-Driven CWE Assessment by Semantic Similarity

  • Gianpietro Castiglione,
  • Giampaolo Bella

摘要

The new frontiers of digital attack and compromise have led to the evolution of security at an organisational level. Recent security regulations and directives require the implementation of specific security measures in the organisations they address. Consequently, organisations need to be compliant with those measures. At the same time, however, the phenomenon of non-compliance is realistic, a scenario in which some measures are ultimately not implemented due to various reasons ranging from ignorance to financial hardship. Of course, this could lead to security flaws. This paper provides a method to carry out a security weakness assessment in an automated manner, starting from the security measures whose implementation is neglected. Such measures are first correlated using semantic similarity to known attack patterns. Then, the correct associations between measures and attack patterns are chosen using two innovative algorithms running on top of the calculated semantic similarity values. The method is demonstrated in the European NIS 2 Directive and the CAPEC catalogue.