SwePub
Sök i LIBRIS databas

  Extended search

onr:"swepub:oai:DiVA.org:kth-91649"
 

Search: onr:"swepub:oai:DiVA.org:kth-91649" > Success Rate of Rem...

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Success Rate of Remote Code Execution Attacks : Expert Assessments and Observations

Holm, Hannes (author)
KTH,Industriella informations- och styrsystem
Sommestad, Teodor (author)
KTH,Industriella informations- och styrsystem
Franke, Ulrik (author)
KTH,Industriella informations- och styrsystem
show more...
Ekstedt, Mathias (author)
KTH,Industriella informations- och styrsystem
show less...
 (creator_code:org_t)
J.UCS consortium, 2012
2012
English.
In: Journal of universal computer science (Online). - : J.UCS consortium. - 0948-695X .- 0948-6968. ; 18:6, s. 732-749
  • Journal article (peer-reviewed)
Abstract Subject headings
Close  
  • This paper describes a study on how cyber security experts assess the importance of three variables related to the probability of successful remote code execution attacks: (i) non-executable memory, (ii) access and (iii) exploits for High or Medium vulnerabilities as defined by the Common Vulnerability Scoring System. The rest of the relevant variables were fixed by the environment of a cyber defense exercise where the respondents participated. The questionnaire was fully completed by fifteen experts. These experts perceived access as the most important variable and availability of exploits for High vulnerabilities as more important than Medium vulnerabilities. Non-executable memory was not seen as significant. Estimates by the experts are compared to observations of actual attacks carried out during the cyber defense exercise. These comparisons show that experts' in general provide fairly inaccurate advice on an abstraction level such as in the present study. However, results also show a prediction model constructed through expert judgment likely is of better quality if the experts' estimates are weighted according to their expertise.

Subject headings

TEKNIK OCH TEKNOLOGIER  -- Elektroteknik och elektronik (hsv//swe)
ENGINEERING AND TECHNOLOGY  -- Electrical Engineering, Electronic Engineering, Information Engineering (hsv//eng)

Keyword

Cyber security
Remote code execution
Software vulnerabilities

Publication and Content Type

ref (subject category)
art (subject category)

Find in a library

To the university's database

  • 1 of 1
  • Previous record
  • Next record
  •    To hitlist

Find more in SwePub

By the author/editor
Holm, Hannes
Sommestad, Teodo ...
Franke, Ulrik
Ekstedt, Mathias
About the subject
ENGINEERING AND TECHNOLOGY
ENGINEERING AND ...
and Electrical Engin ...
Articles in the publication
Journal of unive ...
By the university
Royal Institute of Technology

Search outside SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Close

Copy and save the link in order to return to this view