Please use this identifier to cite or link to this item: https://hdl.handle.net/2440/132139
Citations
Scopus Web of Science® Altmetric
?
?
Type: Conference paper
Title: A queueing solution to reduce delay in processing of disclosed vulnerabilities
Author: Feutrill, A.
Roughan, M.
Ross, J.
Yarom, Y.
Citation: Proceedings of the 2nd IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA 2020), 2020, pp.1-11
Publisher: IEEE
Publisher Place: online
Issue Date: 2020
ISBN: 9781728185439
Conference Name: IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA) (1 Dec 2020 - 3 Dec 2020 : virtual online)
Statement of
Responsibility: 
Andrew Feutrill, Matthew Roughan, Joshua Ross, Yuval Yarom
Abstract: The rate of discovery of vulnerabilities keeps increasing, creating a problem for first responders who need to triage vulnerabilities quickly to decide where to focus their defensive efforts. One of the bottlenecks in this triaging process is the assessment of severity of vulnerabilities and the assignment of the Common Vulnerability Scoring System (CVSS) scores. In this work we study the statistical properties of the vulnerability disclosure process and make two important observations. First, we find that the time series of the number of vulnerability disclosures exhibits a long range dependence, meaning that strong correlations persist over long time periods. Such time series have high variation, high burstiness and slow convergence towards conventional estimators, such as the mean. Our second observation is that the burstiness of the vulnerability disclosure process causes delays in the analysis of vulnerabilities and as a result triaging over 40% of the vulnerabilities takes longer than the median exploit time. Hence, by the time they are analysed and assigned a CVSS score, many vulnerabilities are already being exploited. We propose techniques for modelling and analysing the vulnerability disclosure time series. We further propose reversing the order of triaging vulnerabilities and show, via simulation, that this significantly increases timely triaging of vulnerabilities, reducing the percentage of delayed assessments to 4%.
Keywords: long-range dependence; time series analysis; queueing theory
Rights: ©2020 IEEE
DOI: 10.1109/TPS-ISA50397.2020.00012
Grant ID: http://purl.org/au-research/grants/arc/CE140100049
Published version: https://ieeexplore.ieee.org/xpl/conhome/9325345/proceeding
Appears in Collections:Mathematical Sciences publications

Files in This Item:
There are no files associated with this item.


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.