首页    期刊浏览 2025年05月24日 星期六
登录注册

文章基本信息

  • 标题:Success Rate of Remote Code Execution Attacks - Expert Assessments and Observations
  • 本地全文:下载
  • 作者:H. Holm ; T. Sommestad ; U. Franke
  • 期刊名称:Journal of Universal Computer Science
  • 印刷版ISSN:0948-6968
  • 出版年度:2012
  • 卷号:18
  • 期号:6
  • 页码:732-749
  • 出版社:Graz University of Technology and Know-Center
  • 摘要:This paper describes a study on how cyber security experts assess the importance of three variables related to the probability of successful remote code execution attacks: (i) nonexecutable memory, (ii) access and (iii) exploits for High or Medium vulnerabilities as defined by the Common Vulnerability Scoring System. The rest of the relevant variables were fixed by the environment of a cyber defense exercise where the respondents participated. The questionnaire was fully completed by fifteen experts. These experts perceived access as the most important variable and availability of exploits for High vulnerabilities as more important than Medium vulnerabilities. Non-executable memory was not seen as significant. Estimates by the experts are compared to observations of actual attacks carried out during the cyber defense exercise. These comparisons show that experts’ in general provide fairly inaccurate advice on an abstraction level such as in the present study. However, results also show a prediction model constructed through expert judgment likely is of better quality if the experts’ estimates are weighted according to their expertise.
  • 关键词:Cyber security; Remote code execution; Software vulnerabilities
国家哲学社会科学文献中心版权所有