会议专题

Expert Assessment on the Probability of Successful Remote Code Execution Attacks

This paper describes a study on how cyber security experts assess the importance of three variables related to the probability of successful remote code execution attacks – presence of: (i) non-executable memory, (ii) access and (iii) exploits for High or Medium vulnerabilities as defined by the Common Vulnerability Scoring System. The rest of the relevant variables were fixed by the environment of a cyber defense exercise where the respondents participated. The questionnaire was fully completed by fifteen experts. These experts perceived access as the most important variable and availability of exploits for High vulnerabilities as more important than Medium vulnerabilities. Nonexecutable memory was not seen as significant, however, presumably due to lack of address space layout randomization and canaries in the network architecture of the cyber defense exercise scenario.

Hannes Holm Teodor Sommestad Ulrik Franke Mathias Ekstedt

Department of Industrial Information and Control Systems, The Royal Institute of Technology 100 44 Stockholm, Sweden

国际会议

13th International Conference on Enterprise Information System(第13届企业信息系统国际会议 ICEIS 2011)

北京

英文

1452-1461

2011-06-08(万方平台首次上网日期,不代表论文的发表时间)