An Attack Graph Based Method for Predictive Risk Evaluation of Zero-Day Attacks

  • Marjan Keramati Faculty member of Semnan University
Keywords: Zero day attack, CVSS, Vulnerability, Risk Assessment, Security Metic, Network Hardening, Intrusion Prevention


Performing risk assessment of computer networks is inevitable in the process of network hardening. To do efficient attack prevention, risk evaluation must be done in an accurate and quantitative manner. Such risk assessment requires thorough understanding of attack’s causes or vulnerabilities and their related characteristics. But one major problem is that, there are vulnerabilities that are known by attackers but there is no information about them in databases like NVD (National Vulnerability Database). Such vulnerabilities are referred to as unknown or zero day attacks. Existing standards like NVD ignore the effect of unknown attacks in risk assessment of computer networks. In this paper, by defining some attack graph based security metrics, we proposed an innovative method for risk evaluation of multi-step Zero-Day Attacks. Proposed method by predicting the intrinsic features of Zero-Day attacks makes their risk estimation possible. Considering the effect of Temporal features of vulnerabilities have made our approach a Dynamic Risk Estimator


Marjan Keramati, Faculty member of Semnan University

Marjan Keramati received both her undergraduate and graduate degrees in Computer System Architecture from Iran University of Science and Technology. Currently, she is Faculty Member in Semnan University, Department of Computer Science. Also, she is Editorial Board Member in the International Journal of Cases on Information Technology (USA). Besides, she is the member of National and Technical Commission of Standard Codification and has registered one National Standard in the field of network security in 2017. Publishing papers in International Journals and Conferences, Journal paper reviewing in various prestigious International Journals and being both Scientific and Executive Committee members in International Conferences are the other examples of her academic activities. Her research Interests include: Risk Evaluation, Security Metrics, Security Modeling ,Vulnerability Analysis, Cloud Computing Security, Intrusion Prevention Systems, Intrusion Response Systems.


An Attack Graph Based Method for Predictive Risk Evaluation of Zero-Day Attacks
Keramati, M. (2018, February 17). An Attack Graph Based Method for Predictive Risk Evaluation of Zero-Day Attacks. International Journal of Information & Communication Technology Research, 9(3), 7-16.