簡易檢索 / 詳目顯示

研究生: 朱潮昌
Chao-Chang Chu
論文名稱: 根基於共通脆弱性評估系統(CVSS)之脆弱性管理績效指標研究
Key Performance Indicators of Vulnerability Management based on Common Vulnerability Scoring System V2
指導教授: 楊維寧
Wei-Ning Yang
口試委員: 呂永和
Yung-Ho Leu
陳雲岫
Yun-Shiow Chen
學位類別: 碩士
Master
系所名稱: 管理學院 - 資訊管理系
Department of Information Management
論文出版年: 2012
畢業學年度: 100
語文別: 中文
論文頁數: 43
中文關鍵詞: 脆弱性評估脆弱性管理CVSSCVEVulnerability
外文關鍵詞: CVSS, CVE
相關次數: 點閱:545下載:4
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 鑑別並評估存在於電腦資訊系統中的脆弱性,乃是資訊安全管理要項工作之一。資訊安全管理人員該如何在有限的管理資源中,決定風險處理的優先順序,以有效地降低組織整體資訊安全風險? Common Vulnerability Scoring System (CVSS)提供資訊安全管理人員、資訊安全服務供應商、軟體開發廠商、研究人員一個開放性的架構,以作為脆弱性風險與衝擊的溝通平台。CVSS乃是由Base、Temporal 以及Environmental三個量測群組所構成。由於組織皆具備其獨有的環境特性, Environmental量測群組則特別能反映出組織整體的脆弱性風險,因此Environmental量測群組乃是本研究的主要目標。在Environmental量測群組中,target distribution此一量測值,與組織整體的脆弱性風險值呈現出等比例關係。本研究的目標乃是在於鑑別影響target distribution量測的關鍵因素,從而藉由的參數的適當調整以計算出target distribution量測。本研究顯示,target distribution量測為0~25%時,可確保組織整體脆弱性風險降至低度風險等級。


    One of the major tasks of IT management is to identify and assess vulnerabilities across disparate hardware and software platforms. How can IT managers prioritize these vulnerabilities and remediate those that pose the greatest risk? The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities among IT managers, security vendors, application vendors, and researchers. CVSS consists of three groups: Base, Temporal and Environmental.
    Since the Environmental group which reflects the vulnerability characteristics that are unique to any user’s environment, this research emphasizes on the Environmental group.
    The metric of target distribution in the environmental group approximates the proportion of systems that could be affected by the vulnerability. The goal of this research is to identify the key factors affecting the metric of target distribution and thereby tune the appropriate parameters in the formula for calculating the advisable target distribution metric for an organization to low down vulnerability risk . Results show that in the Environmental metrics group, the metric value of target distribution and vulnerability risk value of the organization show a proportional relationship , and low down the target distribution metric to 0~25% of an organization could make the vulnerabilities risk to Low Level.

    摘 要 I ABSTRACT II 誌 謝 III 目 錄 IV 第1章 緒論 1 1.1 研究背景與動機 1 1.2 研究目的 1 1.3 研究方法 1 1.4 研究流程 2 第2章 文獻探討 4 2.1 共通弱點評估系統 6 2.2 脆弱性評估項目群組 8 2.2.1 基本評估項目群組(Base Metric Group) 9 2.2.2 時序量測項目群組(Temporal Metric Group) 11 2.2.3 環境量測項目群組(Environmental Metric Group) 14 第3章 脆弱性管理績效指標 18 3.1 績效指標與因子(BASE METRICS) 18 3.2 脆弱性環境指標 19 3.3 SUB-EQUATION ADJUSTED BASE SCORE 19 3.4 ADJUSTED BASE SCORE與BASE SCORE的差異 20 3.5 SUB-EQUATION ADJUSTED TEMPORAL 22 3.6 ENVIRONMENTAL SCORE 23 3.6.1 潛在附帶損害Collateral Damage Potential 24 3.6.2 關鍵控制因子Target Distribution 25 3.6.3 Target Distribution Management 28 第4章 結論與建議 30 4.1 研究結論 30 4.2 研究建議 30 參考文獻 32 圖目錄 圖 1 1研究流程 3 圖 2 1共通弱點評估系統整體架構圖 9 圖 2 2 BASE SCORE數學運算式 11 圖 2 3 TEMPORAL SCORE數學運算式 13 圖 2 4 ENVIRONMENTAL SCORE數學運算式 16 圖 3 1脆弱性環境指標關聯 19 圖 3 2 ENVIRONMENTSCORE方程式 23 圖 3 3 TARGET DISTRIBUTION NOT DEFINED 26 圖 3 4 TARGET DISTRIBUTION MEDIUM 27 圖 3 5 TARGET DISTRIBUTION LOW 28 表目錄 表格 2 1基本評估項目群組(BASE METRIC GROUP) 10 表格 2 2時序量測項目群組(BASE METRIC GROUP) 13 表格 2 3環境量測項目群組(BASE METRIC GROUP) 15 表格 3 1 AADJUSTEDBASESCORE可能值 20 表格 3 2 COLLATERAL DAMAGE POTENTIAL說明 24 表格 3 3 TARGET DISTRIBUTION說明 25 表格 3 4 WORLDWIDE OS MARKET SHARE BY VENDOR 29

    [1]http://www.dhs.gov/files/committees/editorial_0353.shtm
    [2]http://www.first.org/
    [3]http://www.cert.org/
    [4]http://www.first.org/cvss/links.html
    [5]http://www.cvedetails.com/cve-details.php?t=1&cve_id=CVE-2012-0670
    [6]樊國楨、林樹國、朱潮昌,「工業控制系統資訊安全風險評鑑實作初探」,資訊安全通訊,民國九十七年。
    [7]http://nvd.nist.gov/cvss.cfm?calculator&adv&version=2
    [8]http://www.cvedetails.com/product/159/Microsoft-All-Windows.htmlvendor_id=26
    [9]經濟部標準檢驗局,經濟部標準檢驗局(2004)風險管理—詞彙—標準使用指導綱要,CNS 14889:2004-01-10。
    [10]「中華民國資訊安全學會(2007)資安資訊分享與分析中心訮討會計畫」之「我國資安資訊分享與分析中心研析報告」,2007-12-03。
    [11]樊國楨、朱潮昌、黃健誠,「資訊安全護理之四:軟體保證」,資訊安全通訊,民國一百年。
    [12]樊國楨等,「資訊安全護理之三:資訊安全管理系統的連續性稽核初探」,資訊安全通訊,民國一百年。
    [13]楊中皇、黃鵬羽,「異質性弱點資料庫整合與研究」,資訊科技國際研討會論文集,2009年。
    [14]王秋艳、张玉清,「一种通用漏洞评级方法」,计算机工程Computer Engineering,第34卷第19期,2008年10月
    英文
    [15]JOHN T. CHAMBERS WORKING GROUP CHAIR CHAIRMAN AND CHIEF EXECUTIVE OFFICER CISCO SYSTEMS, INCORPORATED. VULNERABILITY DISCLOSURE FRAMEWORK FINAL REPORT AND RECOMMENDATIONS BY THE COUNCIL, JOHN W. THOMPSON WORKING GROUP CHAIR CHAIRMAN AND CHIEF EXECUTIVE OFFICERSYMANTEC CORPORATION
    [16]DeLone, W. H., and McLean, E. R. (2003). The DeLone and McLean model of Information system Success: A Complete Guide to the Common Vulnerability Scoring System Version 2.0, 19(4), 9-30.
    [17]Peter Mell, Karen Scarfone ,National Institute of Standards and Technology, Sasha Romanosky Carnegie Mellon University , June, 2007.
    [18]Ayodele Oluwaseun Ibidapo, Pavol Zavarsky(2011). An Analysis of CVSS v2 Environmental Scoring. 2011 IEEE International Conference on Privacy, Security, Risk, and Trust, and IEEE International Conference on Social Computing
    [19]Laurent Gallon, “On the impact of environmental metrics on CVSS score”, The Second IEEE International Conference on Privacy, Security, Risk and Trust, Minneapolis, Minnesota, USA, August 201.
    [20]Karen Scarfone and Peter Mell, “An analysis of CVSS Version 2 Vulnerability Scoring”, National Institute of Standards and Technology (NIST), October 2009.

    QR CODE