Authors
Andrey Fedorchenko, Igor V Kotenko, Andrey Chechulin
Publication date
2015/6
Journal
J. Wirel. Mob. Networks Ubiquitous Comput. Dependable Appl.
Volume
6
Issue
2
Pages
41-57
Description
Security evaluation systems usually use various information sources to estimate computer network security. One of the important tasks in these systems is integration and storage of information from various sources. The paper is devoted to investigation and development of models and methods to integrate open security databases into one repository. The model of integration proposed in the paper helps to improve the accuracy of attack detection systems. As sources for security information, different open databases of vulnerabilities, exploits, and dictionaries of products are used, and open databases of weaknesses, attack patterns and configurations are planned to be used. The object of research and development is the mechanisms intended to bind and combine heterogeneous security information. We propose the structure of the integrated repository and the model of security information integration, describe the repository implementation and analyze the results of experiments with the repository.
Total citations
20152016201720182019202020212022202337526513
Scholar articles
A Fedorchenko, IV Kotenko, A Chechulin - J. Wirel. Mob. Networks Ubiquitous Comput …, 2015