Automated Risk Analysis of a Vulnerability Disclosure Using Active Learning - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

Automated Risk Analysis of a Vulnerability Disclosure Using Active Learning

Résumé

Exhaustively listing the software and hardware components of an information system is non-trivial. This makes it even harder to analyze the risk created by a vulnerability disclosure in the context of a specific information system. Instead of basing the risk analysis of a newly disclosed vulnerability on a possibly obsolete list of components, we focus on the security team members tasked with protecting the information system, by studying how Chief Information Security Officers (CISOs) and their subordinates actually react to vulnerability disclosures. We propose to use active learning to extract the conscious and unconscious knowledge of an information system's security team in order to automate the risk analysis of a newly disclosed vulnerability for a specific information system to be defended.
Fichier principal
Vignette du fichier
2021-cesar_3758460.pdf (484.32 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03515662 , version 1 (06-01-2022)

Identifiants

  • HAL Id : hal-03515662 , version 1

Citer

Clément Elbaz, Louis Rilling, Christine Morin. Automated Risk Analysis of a Vulnerability Disclosure Using Active Learning. C&ESAR 2021 - 28th Computer & Electronics Security Application Rendezvous, Nov 2021, Rennes, France. pp.1-19. ⟨hal-03515662⟩
152 Consultations
333 Téléchargements

Partager

Gmail Facebook X LinkedIn More