Normalization Framework for Vulnerability Risk Management in Cloud

Vulnerability Risk Management (VRM) is a critical element in cloud security that directly impacts cloud providers' security assurance levels. Today, VRM is a challenging process because the dramatic increase of known vulnerabilities (+26% in the last five years), and because it is even more dep...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ahmadi, Vida, Arlos, Patrik, Casalicchio, Emiliano
Format: Tagungsbericht
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:Vulnerability Risk Management (VRM) is a critical element in cloud security that directly impacts cloud providers' security assurance levels. Today, VRM is a challenging process because the dramatic increase of known vulnerabilities (+26% in the last five years), and because it is even more dependent on the organization's context. Moreover, the vulnerability's severity score depends on the Vulnerability Database (VD) selected as a reference in VRM. All these factors introduce a new challenge for security specialists in evaluating and patching the vulnerabilities. This study provides a framework to improve the classification and evaluation phases in vulnerability risk management while using multiple vulnerability databases as a reference. Our solution normalizes the severity score of each vulnerability based on the selected security assurance level. The results of our study highlighted the role of the vulnerability databases in patch prioritization, showing the advantage of using multiple VDs.
DOI:10.1109/FiCloud49777.2021.00022