CVE 동향을 반영한 3-Step 보안 취약점 위험도 스코어링

3-Step Security Vulnerability Risk Scoring considering CVE Trends

초록

As the number of security vulnerabilities increases yearly, security threats continue to occur, and the vulnerability risk is also important. We devise a security threat score calculation reflecting trends to determine the risk of security vulnerabilities. The three stages considered key elements such as attack type, supplier, vulnerability trend, and current attack methods and techniques. First, it reflects the results of checking the relevance of the attack type, supplier, and CVE. Secondly, it considers the characteristics of the topic group and CVE identified through the LDA algorithm by the Jaccard similarity technique. Third, the latest version of the MITER ATT&CK framework attack method, technology trend, and relevance between CVE are considered. We used the data within overseas sites provide reliable security information to review the usability of the proposed final formula CTRS. The scoring formula makes it possible to fast patch and respond to related information by identifying vulnerabilities with high relevance and risk only with some particular phrase.

키워드

사이버 위협 인텔리전스; 위협 산출식; 취약점 위험도; LDA 토픽 모델링; 자카드 유사도; Cyber Threat Intelligence; Threat Scoring; Vulnerability Risk; LDA Topc Modeling; Jaccard Similarity
제목
CVE 동향을 반영한 3-Step 보안 취약점 위험도 스코어링
제목 (타언어)
3-Step Security Vulnerability Risk Scoring considering CVE Trends
저자
임지혜; 이재우
DOI
10.6109/jkiice.2023.27.1.87
발행일
2023-01
저널명
한국정보통신학회논문지
권
27
호
1
페이지
87 ~ 96

파일 다운로드

Thumbnail