The paper deals with the proactive approach to information security risk (ISR) assessment that is an effective way to ensure network protection. This issue can be considered in the work of complex systems or in the process of assessing a safe warehouse in smart manufacturing. ISR is aimed at preventing the exploitation of known vulnerabilities that may exist in a protected network. The ISR assessment is based on vulnerability severity metrics such as base, time, and user environment metrics, as specified in the NIST (National Institute of Standards and Technology) Common Vulnerability Scoring System (CVSS) version 3. The authors have proposed and enhanced a solution for calculating the weighting factors used in the routing decision process. Unlike the time and environment metrics, basic metrics were chosen to characterize the existing vulnerabilities of network elements. This approach allows assessing the overall information security risk of the network, rather than focusing solely on individual cases of compromise. The offered approach involves modifying the calculation of routing metrics to create a model that emphasizes secure routing. It was found that route selection should consider both the basic CVSS metrics and the “communication bandwidth” paths that comprise the route. The objective of this study is to enhance the secure routing model by integrating the basic CVSS indicators and addressing the technical challenges of selecting the optimal route, which is based on a composite indicator that includes both the basic CVSS metric and the bandwidth of the communication channels involved.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Consideration of the CVSS Base Metrics in Building a Mathematical Routing Model Concerning Route Vulnerabilities for Engineering Systems

  • Ganna Pliekhova,
  • Serhii Neronov,
  • Tetiana Volkova,
  • Natalia Ptytsia,
  • Volodymyr Kuzhel

摘要

The paper deals with the proactive approach to information security risk (ISR) assessment that is an effective way to ensure network protection. This issue can be considered in the work of complex systems or in the process of assessing a safe warehouse in smart manufacturing. ISR is aimed at preventing the exploitation of known vulnerabilities that may exist in a protected network. The ISR assessment is based on vulnerability severity metrics such as base, time, and user environment metrics, as specified in the NIST (National Institute of Standards and Technology) Common Vulnerability Scoring System (CVSS) version 3. The authors have proposed and enhanced a solution for calculating the weighting factors used in the routing decision process. Unlike the time and environment metrics, basic metrics were chosen to characterize the existing vulnerabilities of network elements. This approach allows assessing the overall information security risk of the network, rather than focusing solely on individual cases of compromise. The offered approach involves modifying the calculation of routing metrics to create a model that emphasizes secure routing. It was found that route selection should consider both the basic CVSS metrics and the “communication bandwidth” paths that comprise the route. The objective of this study is to enhance the secure routing model by integrating the basic CVSS indicators and addressing the technical challenges of selecting the optimal route, which is based on a composite indicator that includes both the basic CVSS metric and the bandwidth of the communication channels involved.