DEVICE FOR QUANTIFYING VULNERABILITY OF SYSTEM AND METHOD THEREFOR
    3.
    发明申请
    DEVICE FOR QUANTIFYING VULNERABILITY OF SYSTEM AND METHOD THEREFOR 有权
    用于量化系统易损性的装置及其方法

    公开(公告)号:US20160057164A1

    公开(公告)日:2016-02-25

    申请号:US14779435

    申请日:2013-10-21

    Abstract: A method and apparatus for quantifying the vulnerability of a system. The apparatus includes a vulnerability calculation unit, a target organization security level calculation unit, a network separation status calculation unit, an interim calculation unit, and a final score calculation unit. The vulnerability calculation unit converts each of the vulnerability identification results of the system into a vulnerability score. The target organization security level calculation unit calculates a target organization security level score based on a technology-field security level score and a management-field security level score. The network separation status calculation unit converts the status of the separation of the local network of the system into a network separation score. The interim calculation unit calculates an interim score. The final score calculation unit quantifies the vulnerability of the system by finally calculating a composite score using the interim score and a simulated intrusion success level.

    Abstract translation: 一种量化系统脆弱性的方法和装置。 该装置包括漏洞计算单元,目标组织安全级别计算单元,网络分离状态计算单元,临时计算单元和最终得分计算单元。 漏洞计算单元将系统的每个漏洞识别结果转换为漏洞得分。 目标组织安全等级计算单元基于技术领域的安全等级得分和管理域安全级别得分来计算目标组织安全级别得分。 网络分离状态计算单元将系统的本地网络的分离状态转换为网络分离分数。 临时计算单位计算临时评分。 最终得分计算单元通过使用临时得分和模拟入侵成功水平最终计算综合得分来量化系统的脆弱性。

Patent Agency Ranking