Quantitative security analysis of network OSes by fitting VDM and examining CVSS
HyunChul Joh · 2018
Computers without connections to the outside world considered as almost useless tools these days. Network equipment, such as routers and switches, is one of the most critical resources in this everything-is-connected world. Hence, a vulnerable network device might cause a significantly negative effect to related organizations. In this paper, we quantitatively analyze the two network OSes, Cisco IOS and Juniper JUNOS in the security vulnerability point of view. We first, apply a vulnerability discovery model on both systems, and estimate the future behaviors of the discovery trends. Then the severity of vulnerabilities with CVSS and types of vulnerabilities discovered are also examined. The analysis shows that a vulnerability discovery model represents properly the discovery trends for the network OSes. Also the result shows that most of the time vulnerabilities in network OSes are compromised via remote networks with no authentication required systems.