A Cost-effective Automation Method of Massive Vulnerabilities Analysis and Remediation Based on Cloud Native
Tian Hu, Shangyuan Zhuang, Jiyan Sun, Yinlong Liu, Wei Ma, Hongchao Wang · 2023
With the rapid development of the cutting edge cloud computing technology, millions of vulnerabilities have been identified, there is a growing concern that organizations should devote plenty of time and lots of resources to secure. The overarching objective of remediation is to prioritize the vulnerabilities. Hence, define the severity and the urgency of the vulnerabilities and remediate them automatically is very important. Although the recognized Common Vulnerability Scoring System (CVSS) 4.0 method addresses this issues partly, they are difficult to be implemented in practices on the cloud because of the complication and lack of risk based factors.To this end, we propose a Cost-effective Massive Automation Method of Vulnerability Analysis and Remediation Based on Cloud Native Framework. Specifically, considering that the current CVSS is more like a severity of vulnerabilities, we design a novel formula to define the urgency of vulnerabilities. The formula takes the advantaged of the capabilities of modern cloud-based infrastructure and simplifies the CVSS. Besides, we propose an algorithm of risk reduction by leveraging the cloud native security capabilities, which cut down unnecessary patching time and workload. Particularly, in order to remediation the risk on the cloud, we implement an automatic scheme to harden the vulnerabilities by invoking the cloud native APIs based on the Security Orchestration, Automation and Response (SOAR) platform. Finally, we conduct comprehensive experiments to evaluate our system. Experimental results demonstrate the effectiveness of ours approach has a high ratio of urgency risk recognition of 99.24%. Meanwhile, ours approach shows a maximum risk reduction by downgrade the fixable vulnerability with a average of 79% risk reduction rate in application level and 99% of risk reduction rate in operating system level respectively. As a result, our approach lightens the workload of patching greatly in the real cloud computing environment.