Estimating Mean Time to Compromise Using Non-homogenous Continuous-Time Markov Models

Subil Abraham · 2016

Mean time to compromise is a commonly used comparative metric to determine a system's weakness and aid in risk mitigation strategies. In this paper, we provide a unified framework for measuring a network's mean time to compromise by considering both the skill level of an attacker as well as the causal relationship that exists between all the vulnerabilities in the network. Unlike existing approaches, we provide a methodology for estimating the skill coefficient of different categories of attackers (Beginner, Intermediate, Expert) by analyzing 15 years of vulnerability data in the NVD database. We then extend our predictive cybersecurity stochastic model into a nonhomogeneous continuous model to derive the overall mean time to compromise by modeling the sojourn time in each state as a random variable based on the skill level of an attacker. Finally, we demonstrate through a case study how our framework can enable security practitioners to visualize the future security state and optimize the necessary steps to harden the enterprise network from external threats.

Read the paper · More papers on PaperTik