RMIT University
Browse

Vulnerability Modelling for Hybrid IT Systems

conference contribution
posted on 2024-11-03, 14:46 authored by Attiq Ur-Rehman, Iqbal GondalIqbal Gondal, Joarder Kamruzzaman, Alireza Jolfaei
Common vulnerability scoring system (CVSS) is an industry standard that can assess the vulnerability of nodes in traditional computer systems. The metrics computed by CVSS would determine critical nodes and attack paths. However, traditional IT security models would not fit IoT embedded networks due to distinct nature and unique characteristics of IoT systems. This paper analyses the application of CVSS for IoT embedded systems and proposes an improved vulnerability scoring system based on CVSS v3 framework. The proposed framework, named CVSS IoT , is applied to a realistic IT supply chain system and the results are compared with the actual vulnerabilities from the national vulnerability database. The comparison result validates the proposed model. CVSS IoT is not only effective, simple and capable of vulnerability evaluation for traditional IT system, but also exploits unique characteristics of IoT devices.

History

Start page

1186

End page

1191

Total pages

6

Outlet

Proceedings of the 20th IEEE International Conference on Industrial Technology (ICIT 2019)

Name of conference

ICIT 2019

Publisher

IEEE

Place published

United States

Start date

2019-02-13

End date

2019-02-15

Language

English

Copyright

© 2019 IEEE.

Former Identifier

2006109855

Esploro creation date

2021-10-22

Usage metrics

    Scholarly Works

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC