ACM Transactions on Privacy and Security · 2018 · 63 citations · 23 references
EngineeringInformation SecuritySoftware SystemsSecurity AssessmentSoftware EngineeringSoftware AnalysisCybersecurity EngineeringVulnerability AnalysisVulnerability Assessment (Computing)Systems EngineeringSystem SecurityOperational SoftwareDefense SystemsNetworked Computer SystemsComputer EngineeringComputer ScienceThreat CharacterizationVulnerability RemediationSecurity Testing MethodSoftware SecurityProgram AnalysisSoftware TestingVulnerability DiscoverySecurity MeasurementVulnerability Control
Vulnerability remediation is a critical task in operational software and network security management. This article develops and evaluates an effective vulnerability management strategy called VULCON (VULnerability CONtrol). VULCON employs a mixed‑integer multiobjective optimization algorithm that ingests real vulnerability scan reports, asset criticality, and personnel resources to prioritize patching, thereby optimizing time‑to‑remediation and total exposure while respecting resource constraints, and has been tested on real CSOC data. VULCON achieved an 8.97 % reduction in total vulnerability exposure, can compute monthly resource requirements to maintain a target TVE, and provides operational guidance for CSOCs.
Vulnerability remediation is a critical task in operational software and network security management. In this article, an effective vulnerability management strategy, called VULCON (VULnerability CONtrol), is developed and evaluated. The strategy is based on two fundamental performance metrics: (1) time-to-vulnerability remediation (TVR) and (2) total vulnerability exposure (TVE). VULCON takes as input real vulnerability scan reports, metadata about the discovered vulnerabilities, asset criticality, and personnel resources. VULCON uses a mixed-integer multiobjective optimization algorithm to prioritize vulnerabilities for patching, such that the above performance metrics are optimized subject to the given resource constraints. VULCON has been tested on multiple months of real scan data from a cyber-security operations center (CSOC). Results indicate an overall TVE reduction of 8.97% when VULCON optimizes a realistic security analyst workforce’s effort. Additionally, VULCON demonstrates that it can determine monthly resources required to maintain a target TVE score. As such, VULCON provides valuable operational guidance for improving vulnerability response processes in CSOCs.
23
IEEE Software · 2011 · 2K citations
On the complexity of integer programming
Christos H. Papadimitriou · Journal of the ACM · 1981 · 552 citations · Full text