Common Vulnerabilities and Exposures : Analyzing the Development of Computer Security Threats
Andrew Kronser · Työväentutkimus Vuosikirja · 2020
Algorithms study trackComputer security professionals are at several disadvantages compared to the adversaries that seek to exploit computer systems.The Common Vulnerabilities and Exposures list was introduced in 1999 to make information more readily accessible in service of tool interoperability, risk sharing, and effective communication.The goal of this thesis is to leverage techniques in unsupervised learning and data mining in order to identify and visualize patterns in the development of threats over the lifespan of this list.We consider multi-dimensional clustering using K-medoids and hierarchical clustering.We also consider three methods for segmentation: segmentation optimized for an additive cost function using dynamic programming, monotonic segmentation of exponentially distributed data, and a method for multinomial change point detection that measures the divergence between static and dynamic parameter estimators.We find that there is signal between the exploit types and products.Certain product types also experience more severe exploits on average.A monotonic segmentation of delay traces indicates that the number of identified threats proliferates over the supported lifespan of large products.Finally, the composition of threat types has notably diversified since 2018.