Visible to the public A Quantitative CVSS-Based Cyber Security Risk Assessment Methodology for IT Systems

TitleA Quantitative CVSS-Based Cyber Security Risk Assessment Methodology for IT Systems
Publication TypeConference Paper
Year of Publication2017
AuthorsAksu, M. U., Dilek, M. H., Tatlı, E. İ, Bicakci, K., Dirik, H. İ, Demirezen, M. U., Aykır, T.
Conference Name2017 International Carnahan Conference on Security Technology (ICCST)
KeywordsAttack Graphs, big data security metrics, computer security, cyber security risk assessment methodology, cyber security risks, cyber threats, detailed risk assessment, graph theory, high level risk metrics, IT systems, Measurement, Metrics, Organizations, probability, pubcrawl, quantitative CVSS, Resiliency, risk assessment, risk management, risk management frameworks, risk metrics, risk metrics values, risk views, Scalability, security of data, Standards, system risk assessments, Vulnerability, Vulnerability Management
Abstract

IT system risk assessments are indispensable due to increasing cyber threats within our ever-growing IT systems. Moreover, laws and regulations urge organizations to conduct risk assessments regularly. Even though there exist several risk management frameworks and methodologies, they are in general high level, not defining the risk metrics, risk metrics values and the detailed risk assessment formulas for different risk views. To address this need, we define a novel risk assessment methodology specific to IT systems. Our model is quantitative, both asset and vulnerability centric and defines low and high level risk metrics. High level risk metrics are defined in two general categories; base and attack graph-based. In our paper, we provide a detailed explanation of formulations in each category and make our implemented software publicly available for those who are interested in applying the proposed methodology to their IT systems.

URLhttp://ieeexplore.ieee.org/document/8167819/
DOI10.1109/CCST.2017.8167819
Citation Keyaksu_quantitative_2017