Skip to main content

2017 | OriginalPaper | Buchkapitel

Dynamically-Enabled Defense Effectiveness Evaluation in Home Internet Based on Vulnerability Analysis

verfasst von : Ting Wang, Min Lei, Jingjie Chen, Shiqi Deng, Yu Yang

Erschienen in: Cloud Computing and Security

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Current intelligent devices in Home Internet, such as routers and cameras, have suffered malicious attacks from hackers. Therefore, security for Home Internet appears particularly significant. In order to have a quantitative evaluation of security defense ability of Home Internet system, this paper proposes an improved vulnerability scoring method on Home Internet based on Information Security Technology Security Vulnerability Classification Guide. Compared to original scoring method which is mainly based on Internet, this improved scoring performs differently. It’s aimed to have a quantitative evaluation on security defense effectiveness of Home Internet system: higher vulnerability score indicates higher threaten degree and relatively weak defense ability. In this paper, the Home Internet system takes dynamically-enabled defense technology (randomly changes system status) to make defense. Through calculating vulnerability scores before and after random changes of system status, this paper succeeds in making a quantitative evaluation on security defense ability of Home Internet system.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Yang, Y., et al.: General theory of security and a study case in internet of things. IEEE Internet Things J. 4(2), 1 (2016) Yang, Y., et al.: General theory of security and a study case in internet of things. IEEE Internet Things J. 4(2), 1 (2016)
2.
Zurück zum Zitat Verma, H., Jain, M., Goel, K., Virkram, A., Verma, G.: Smart home system based on Internet of Things. In: 2016 3rd International Conference on Computing for Sustainable Global Development (INDIACom), pp. 2073–2075. IEEE, 31 October 2016 Verma, H., Jain, M., Goel, K., Virkram, A., Verma, G.: Smart home system based on Internet of Things. In: 2016 3rd International Conference on Computing for Sustainable Global Development (INDIACom), pp. 2073–2075. IEEE, 31 October 2016
3.
Zurück zum Zitat Salamat, B., Jackson, T., Wagner, G., et al.: Runtime defense against code injection attacks using replicated execution. IEEE Trans. Dependable Secure Comput. 8(4), 588–601 (2011)CrossRef Salamat, B., Jackson, T., Wagner, G., et al.: Runtime defense against code injection attacks using replicated execution. IEEE Trans. Dependable Secure Comput. 8(4), 588–601 (2011)CrossRef
4.
Zurück zum Zitat Lin, Y., Quan, Y.: Dynamially-Enabled Cyberspace Defense, 1st edn. The People’s Posts and Telecommunications Press (Posts & Telecom Press), Beijing (2016). pp. 214–215 Lin, Y., Quan, Y.: Dynamially-Enabled Cyberspace Defense, 1st edn. The People’s Posts and Telecommunications Press (Posts & Telecom Press), Beijing (2016). pp. 214–215
5.
Zurück zum Zitat Liu, Y., Hu, S., Ho, T.-Y.: Vulnerability assessment and defense technology for smart home cybersecurity considering pricing cyberattacks. In: Computer-Aided Design (ICCAD), pp. 183-190. IEEE, 08 January 2015 Liu, Y., Hu, S., Ho, T.-Y.: Vulnerability assessment and defense technology for smart home cybersecurity considering pricing cyberattacks. In: Computer-Aided Design (ICCAD), pp. 183-190. IEEE, 08 January 2015
6.
Zurück zum Zitat Antunes, N., Vieira, M.: Defending against Web Application Vulnerabilities. Computer 45(2), 66–72 (2011)CrossRef Antunes, N., Vieira, M.: Defending against Web Application Vulnerabilities. Computer 45(2), 66–72 (2011)CrossRef
7.
Zurück zum Zitat Liu, Q., Zhang, Y., Zhang, Y., et al.: Research on key technologies of security vulnerability classification. J. Commun. (s1), 79–87 (2012) Liu, Q., Zhang, Y., Zhang, Y., et al.: Research on key technologies of security vulnerability classification. J. Commun. (s1), 79–87 (2012)
8.
Zurück zum Zitat Srivatsa, M., Liu, L.: Vulnerabilities and security threats in structured overlay networks: a quantitative analysis. In: 2004 20th Annual Computer Security Applications Conference. IEEE, pp. 252–261 (2005) Srivatsa, M., Liu, L.: Vulnerabilities and security threats in structured overlay networks: a quantitative analysis. In: 2004 20th Annual Computer Security Applications Conference. IEEE, pp. 252–261 (2005)
9.
Zurück zum Zitat Li, X., Chang, X., John, A.B., et al.: A novel approach for software vulnerability classification. In: 2017 Annual Reliability and Maintainability Symposium (RAMS), pp. 1–7. IEEE, 30 March 2017 Li, X., Chang, X., John, A.B., et al.: A novel approach for software vulnerability classification. In: 2017 Annual Reliability and Maintainability Symposium (RAMS), pp. 1–7. IEEE, 30 March 2017
10.
Zurück zum Zitat Jin, S., Wang, Y., Cui, X., et al.: A review of classification method for network vulnerability. In: IEEE International Conference on System, Man and Cybernetics (SMC), pp. 1171–1175. IEEE, 04 December 2009 Jin, S., Wang, Y., Cui, X., et al.: A review of classification method for network vulnerability. In: IEEE International Conference on System, Man and Cybernetics (SMC), pp. 1171–1175. IEEE, 04 December 2009
Metadaten
Titel
Dynamically-Enabled Defense Effectiveness Evaluation in Home Internet Based on Vulnerability Analysis
verfasst von
Ting Wang
Min Lei
Jingjie Chen
Shiqi Deng
Yu Yang
Copyright-Jahr
2017
DOI
https://doi.org/10.1007/978-3-319-68542-7_71