arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

建模本地利用风险——用于量化利用风险和运营效率的贝叶斯框架

Modeling Local Exploit Hazard - A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency

Stephen Shaffer, Laura Voicu

arXiv 2607.24618首次发表:更新:

AI 中文总结

提出贝叶斯框架的本地利用风险模型,将ELM全局概率转化为组织资产每日利用风险率,经专家意见和多种测试更新,用生存分析技术转换为风险率,可汇总排序候选补救措施,为防御者提供定量优先级排序基础,未来有相关扩展工作。

AI 中文摘要

本文提出了一种本地利用风险模型,即一个贝叶斯框架,它将诸如漏洞利用预测评分系统(EPSS)等利用可能性模型(ELM)产生的全局概率转换为组织自身资产的每日利用风险率。该模型将已部署控制措施的利用预防有效性衡量为概率分布。该分布源于主题专家意见库,并通过遥测、漏洞与攻击模拟或渗透测试中的贝塔 - 二项式推理进行更新,然后通过攻击向量对齐应用于ELM分数。使用标准生存分析技术将所得的每个漏洞利用可能性转换为风险率,支持恒定指数风险和威布尔风险,其形状参数根据已知被利用漏洞目录时间校准,捕获随着漏洞老化利用风险的经验衰减。由于风险在独立性下是可加的,每个漏洞的风险率通过求和汇总到主机、网络、业务部门和组织。通过预计的风险降低对候选补救措施进行模拟和排序,为防御者在固定能力下进行优先级排序提供了可辩护的定量基础。未来工作包括事件可能性和财务损失建模的扩展。

英文摘要

This paper presents a local exploit hazard model : a Bayesian framework that converts the global probabilities produced by an exploit likelihood model (ELM), such as the Exploit Prediction Scoring System (EPSS), into a daily exploit hazard rate for an organization's own assets. The model measures the exploit-prevention effectiveness of deployed controls as a probability distribution. That distribution is seeded from a subject-matter-expert opinion pool and updated through Beta-Binomial inference from telemetry, breach-and-attack simulation, or penetration testing, then applied to ELM scores by attack-vector alignment. The resulting per-vulnerability exploitation likelihoods are converted into hazard rates using standard survival-analysis techniques, supporting both a constant exponential hazard and a Weibull hazard whose shape parameter, calibrated from Known Exploited Vulnerabilities catalog timing, captures the empirical decay of exploitation risk as a vulnerability ages. Because hazards are additive under independence, per-vulnerability rates aggregate by summation up to host, network, business unit, and organization. Candidate remediation actions are simulated and ranked by projected hazard reduction, giving defenders a defensible, quantitative basis for prioritization under fixed capacity. Future work includes extensions for incident likelihood and financial loss modeling.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑