• skip to content
  • skip to navigation
  • skip to supporting content
Homepage
CLOK - Central Lancashire Online Knowledge
Menu
  • Home
  • About
  • Policies
  • Deposit Guide: Research eTheses
  • Copyright Guide
  • Contact
  • Links
    • Login
  • Deposit
  • Search Item
  • Search FullText
  • Browse

Estimating ToE Risk Level Using CVSS

Tools
- Tools
+ Tools

Houmb, Siv Hilde and Franqueira, Virginia N.L. (2009) Estimating ToE Risk Level Using CVSS. In: ARES 2009: Proceedings of the The Forth International Conference on Availability, Reliability and Security, March 16-19, 2009, Fukuoka, Japan.

[img] PDF - Published Version
Restricted to Repository staff only

315Kb

Official URL: http://dx.doi.org/10.1109/ARES.2009.151

Abstract

Security management is about calculated risk and requires continuous evaluation to ensure cost, time and resource effectiveness. Parts of which is to make future-oriented, cost benefit investments in security. Security investments must adhere to healthy business principles where both security and financial aspects play an important role. Information on the current and potential risk level is essential to successfully trade-off security and financial aspects.
Risk level is the combination of the frequency and impact of a potential unwanted event, often referred to as a security threat or misuse. The paper presents a risk level estimation model that derives risk level as a conditional probability over frequency and impact estimates. The frequency and impact estimates are derived from a set of attributes specified in the Common Vulnerability Scoring System (CVSS). The model works on the level of vulnerabilities (just as the CVSS) and is able to compose vulnerabilities into service levels. The service levels define the potential risk levels and are modelled as a Markov process, which are then used to predict the risk level at a particular time.


Item Type:Conference or Workshop Item (Paper)
Uncontrolled Keywords (separate with ;):Quantifying security; Operational security; Risk estimation; Calculated risk and CVSS
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Schools:School of Computing Engineering & Physcial Sciences
ID Code:6010
Deposited By: Virginia Nunes Leal Franqueira
Deposited On:01 Nov 2012 11:54
Last Modified:01 Nov 2012 11:54

Repository Staff Only: item control page

University of Central Lancashire

Preston,
Lancashire,
PR1 2HE

Tel: +44 (0)1772 201 201

Other Links

  • Contact UCLan
  • How to find us
  • Help

  • Facebook
  • Twitter
  • UCLan RSS
  • Contact UCLan
  • Copyright |
  • Disclaimer |
  • Data Protection Act |
  • Freedom of Information