Composite Metrics for Network Security Analysis
Simon Yusuf Enoch, Jin B. Hong, Mengmeng Ge, Dong Seong Kim

TL;DR
This paper introduces a systematic classification of network security metrics based on reachability information and proposes a method to develop composite metrics using Hierarchical Attack Representation Models.
Contribution
It provides a novel classification framework for security metrics and a new methodology for creating composite metrics with HARM.
Findings
Classified security metrics into host-based and network-based categories.
Developed a method to compute composite security metrics using HARM.
Enhanced understanding of security assessment through systematic classification.
Abstract
Security metrics present the security level of a system or a network in both qualitative and quantitative ways. In general, security metrics are used to assess the security level of a system and to achieve security goals. There are a lot of security metrics for security analysis, but there is no systematic classification of security metrics that are based on network reachability information. To address this, we propose a systematic classification of existing security metrics based on network reachability information. Mainly, we classify the security metrics into host-based and network-based metrics. The host-based metrics are classified into metrics ``without probability" and "with probability", while the network-based metrics are classified into "path-based" and "non-path based". Finally, we present and describe an approach to develop composite security metrics and it's calculations…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
