A Survey on Systems Security Metrics

Abstract

Security metrics have received significant attention. However, they have not been systematically explored based on the understanding of attack-defense interactions, which are affected by various factors, including the degree of system vulnerabilities, the power of system defense mechanisms, attack (or threat) severity, and situations a system at risk faces. This survey particularly focuses on how a system security state can evolve as an outcome of cyber attack-defense interactions. This survey concerns how to measure system-level security by proposing a security metrics framework based on the following four sub-metrics: (1) metrics of system vulnerabilities , (2) metrics of defense power , (3) metrics of attack or threat severity , and (4) metrics of situations . To investigate the relationships among these four sub-metrics, we propose a hierarchical ontology with four sub-ontologies corresponding to the four sub-metrics and discuss how they are related to each other. Using the four sub-metrics, we discuss the state-of-art existing security metrics and their advantages and disadvantages (or limitations) to obtain lessons and insight in order to achieve an ideal goal in developing security metrics. Finally, we discuss open research questions in the security metrics research domain and we suggest key factors to enhance security metrics from a system security perspective.

Document Details

Document Type
Pub Defense Publication
Publication Date
Dec 20, 2016
Source ID
10.1145/3005714

Entities

People

  • Jin-Hee Cho
  • Marcus Pendleton
  • Richard Garcia-lebron
  • Shouhuai Xu

Organizations

  • Office of the Secretary of Defense
  • United States Army Research Laboratory
  • University of Texas at San Antonio

Tags

Fields of Study

  • Computer science
  • Engineering

Readers

  • Cybersecurity.
  • Software Engineering.
  • Systems Analysis and Design

Technology Areas

  • Cyber