Evaluation of Attacker Skill Level for Multi-stage Attacks
Terézia Mézešová, Pavol Sokol, Tomáš Bajtoš · 2019
Information security risks caused by difficult to exploit vulnerabilities are often treated with countermeasures as last due to their low likelihood of occurrence and should be given a high priority in security monitoring. In this paper, we propose an evaluation of detected attacks in terms of their difficulty - by assigning them an attacker's skill level. We draw similarities between vulnerability's exploitability score and aim to evaluate intrusion detection system alerts within the same framework. We also present the methodology on attacks from a dataset intended for evaluation of intrusion detection systems.