异构网络的协同漏洞管理:自适应两阶段漏洞评估、上下文感知风险优先级排序与自动缓解
Orchestrated Vulnerability Management for Heterogeneous Networks: Adaptive Two-Stage Vulnerability Assessment, Context-Aware Risk Prioritization, and Automated Mitigation
浏览论文内容
中文总结 AI 辅助
本文针对异构网络安全挑战,提出SOAR编排的漏洞管理框架,通过自适应两阶段评估、上下文感知风险排序及自动SDN/IDS缓解,减少扫描与评估时间、降低需立即缓解的漏洞占比,实现高效可扩展的漏洞管理。
中文摘要 AI 辅助
异构网络因设备多样性、脆弱运行条件及异构固件与服务配置带来重大安全挑战。传统漏洞管理常依赖静态扫描与基于严重程度的优先级排序,忽视利用可能性与资产上下文,这会延迟缓解并增加运营开销。本文提出一种SOAR编排的漏洞管理框架,整合被动资产发现、自适应两阶段漏洞评估、上下文感知风险评估及基于SDN的自动缓解。检测引擎利用适配设备能力的评估策略逐步表征设备攻击面,最小化对资源受限IoT资产的干扰。风险评估结合CVSS严重程度、EPSS利用概率及上下文属性,按运营风险对漏洞排序。基于风险等级,通过协调OpenFlow与IDS策略自动执行缓解,范围从监控、选择性服务隔离到完整主机隔离。实验结果验证了框架的有效性:自适应两阶段评估将扫描时间最多减少91%,同时在初始阶段识别出71%的基准漏洞后,选择性触发进一步分析;上下文感知风险模型将需立即缓解的漏洞减少约75%,且未遗漏任何经验证存在利用可能的漏洞;与传统评估相比,该框架将32台物理主机的评估时间最多减少45%,并在毫秒内执行缓解,通过自适应评估、上下文感知优先级排序与自动缓解实现高效且可扩展的漏洞管理。
英文摘要
Heterogeneous networks pose significant security challenges due to device diversity, fragile operating conditions, and heterogeneous firmware and service configurations. Traditional vulnerability management often relies on static scanning and severity-based prioritization, overlooking exploitation likelihood and asset context. This can delay mitigation and increase operational overhead. This paper proposes a SOAR-orchestrated vulnerability management framework integrating passive asset discovery, adaptive two-stage vulnerability assessment, context-aware risk assessment, and automated SDN-based mitigation. The detection engine progressively characterizes device attack surfaces using assessment strategies tailored to device capabilities, minimizing disruption to resource-constrained IoT assets. Risk assessment combines CVSS severity, EPSS exploitation probability, and contextual attributes to prioritize vulnerabilities by operational risk. Based on risk bands, mitigation is automatically enforced through coordinated OpenFlow and IDS policies, ranging from monitoring and selective service isolation to complete host quarantine. Experimental results demonstrate the framework's effectiveness. Adaptive two-stage assessment reduces scan time by up to 91% while identifying 71% of baseline vulnerabilities during the initial stage before selectively triggering further analysis. The context-aware risk model reduces vulnerabilities requiring immediate mitigation by approximately 75% without missing any vulnerability with verified exploitation. Compared with conventional assessment, the framework reduces assessment time for 32 physical hosts by up to 45% and enforces mitigation within milliseconds, enabling efficient and scalable vulnerability management through adaptive assessment, context-aware prioritization, and automated mitigation.