DRASN-DynaRose Attack Surface Management for Network Security Analysis and Enforcement
摘要
Enterprises face increasingly cybersecurity challenges due to expanding digital infrastructures and complex IT environments. Existing attack surface management methods lack practical method and fail to account for asset importance, and are insufficient as guidance on cybersecurity efforts. To address this issue, we propose the DynaRose Attack Surface Management (DRASM) framework. Firstly in DRASM, a practical asset vulnerability priority rating method, DynaRose Vulnerability Priority Rating (DRVPR) that considers exploitability and cumulative vulnerability effects without requiring extensive data, is proposed. Secondly, we introduced an attack impacting assessment method based on asset value, allowing impact assessments from the asset owner’s perspective. Furthermore, an objective attack surface scoring method for enterprise networks is developed, along with attack surface reduction methods considering budget constraints. Simulation results demonstrate that the proposed methods effectively reduce the attack surface and enhance network security with limited budgets. The DRASM offers a comprehensive framework for enterprises to assess and mitigate risks, aligning security efforts with asset value and operational priorities.