A New Framework for Ranking Vulnerabilities in the Clouds
He Zhu

TL;DR
This paper introduces a novel framework that assesses and ranks vulnerabilities in cloud services by analyzing service dependency graphs, improving security prioritization across diverse cloud infrastructures.
Contribution
The paper proposes a flexible framework that integrates with various algorithms and cloud setups to effectively evaluate and rank vulnerabilities based on their threat levels.
Findings
Framework successfully ranks vulnerabilities in cloud environments.
AssetRank algorithm integrated and validated within the framework.
Experiments demonstrate improved vulnerability assessment accuracy.
Abstract
Qualifying and ranking threat degrees of vulnerabilities in cloud service are known to be full of challenges. Although there have been several efforts aiming to address this problem, most of them are too simple or cannot be applied into cloud infrastructure. This paper aims to propose a novel framework to qualify and rank the vulnerabilities based on their threat degrees in cloud service. Through inputting or constructing service dependency graph, our framework is able to generate the importance degree of each service and the ranking list of all the vulnerabilities in cloud service. Moreover, our framework can be adopted not only into various cloud infrastructures, but also different categories of algorithms according to concrete requirements. To evaluate our framework, we adopt AssetRank algorithm into the framework, and present the whole design of our work. Comprehensive experiments…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCloud Data Security Solutions · Cloud Computing and Resource Management · Data Quality and Management
