arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.14888cs.CR

面向中小企业组织网络安全的经验性概率风险显现模型

Toward an Empirical Probabilistic Risk Manifestation Model of Organizational Cybersecurity in SMEs

  • Louisiana State University(路易斯安那州立大学)

机构由 AI 辅助整理,请以论文原文为准。

FNU Nurjahan, Aidan Eiler, Mst Eshita Khatun, Lamine Noureddine, Aisha Ali-Gombe

中文总结 AI 辅助

本研究基于22家中小企业的281项安全发现,提出经验性风险显现模型,识别八项组织安全功能及主导风险路径,并证明精简评估可减少24%负担且保留97%关键发现。

中文摘要 AI 辅助

本文对中小企业(SMEs)的组织网络安全风险进行了跨层经验性研究,分析了来自22个真实世界中小企业网络安全评估中的281个经过验证的安全发现,这些评估是在两年内通过一家公益大学网络安全诊所进行的。我们首先通过迭代主题编码识别反复出现的组织安全功能,然后估计一个经验性风险显现模型,将该模型与暴露条件、攻击机制和网络安全结果联系起来,并使用概率传播来识别主导风险路径。该模型描述了在此样本中观察到的经验性关联,而非因果或预测关系。我们的分析识别出八个组织安全功能,与两种暴露条件、五种攻击机制和六种结果类别相关联。在大多数功能中,主导路径遵循资产暴露到凭证泄露再到未授权访问的路径,而基础设施和网络安全主要通过网络暴露传播;这些路径在留一组织分析中保持稳定。最后,我们评估了中小企业网络安全评估是否可以在保持有意义的安全覆盖的同时进行简化。保留六个功能可将评估负担减少24%,同时保留97%的关键发现和92%的风险路径覆盖,这是一种安全导向的缩减;而保留五个功能可将负担减少45%,同时保留89%的关键发现和85%的风险路径覆盖,这是一种更注重效率的替代方案。

英文摘要

In this paper, we present a cross-layer empirical study of organizational cybersecurity risk in Small and medium-sized enterprises (SMEs), analyzing 281 validated security findings from 22 real-world SME cybersecurity assessments conducted over two years through a pro bono university cybersecurity clinic. We first identify recurring organizational security functions through iterative thematic coding, then estimate an empirical Risk Manifestation Model linking these functions to exposure conditions, attack mechanisms, and cybersecurity outcomes, and use probability propagation to identify dominant risk pathways. The model characterizes empirical associations observed in this sample rather than causal or predictive relationships. Our analysis identifies eight organizational security functions associated with two exposure conditions, five attack mechanisms, and six outcome categories. Across most functions, the dominant pathway follows asset exposure to credential compromise to unauthorized access, whereas infrastructure and network security primarily propagates through network exposure; these pathways remain stable under leave-one-organization-out analysis. Finally, we evaluate whether SME cybersecurity assessments can be simplified while preserving meaningful security coverage. Retaining six functions reduces assessment burden by 24% while preserving 97% of critical findings and 92% of risk-pathway coverage, a security-oriented reduction, while retaining five functions reduces burden by 45% while preserving 89% of critical findings and 85% of risk-pathway coverage, a more efficiency-oriented alternative.

↑