Visible to the public On Coverage-Based Attack Profiles

TitleOn Coverage-Based Attack Profiles
Publication TypeConference Proceedings
Year of Publication2014
AuthorsRivers, Anthony T., Vouk, Mladen A., Williams, Laurie
Conference NameEight International Conference on Software Security and Reliability (SERE)
Series TitleFast Abstracts
Pagination5-6
Conference LocationSan Francisco, CA
KeywordsNCSU, Vulnerability and Resilience Prediction Models
Abstract

Automated cyber attacks tend to be schedule and resource limited. The primary progress metric is often "coverage" of pre-determined "known" vulnerabilities that may not have been patched, along with possible zero-day exploits (if such exist). We present and discuss a hypergeometric process model that describes such attack patterns. We used web request signatures from the logs of a production web server to assess the applicability of the model.

Citation Keynode-22647
Refereed DesignationRefereed