A trend analysis of exploitations
Browne, H.K.; Arbaugh, W.A.; McHugh, J.; Fithen, W.L.
Security and Privacy, 2001. S&P 2001. Proceedings. 2001 IEEE Symposium on
Volume , Issue , 2001 Page(s):214 - 229
Digital Object Identifier 10.1109/SECPRI.2001.924300
Summary:We have conducted an empirical study of a number of computer
security exploits and determined that the rates at which incidents
involving the exploit are reported to CERT can be modeled using a common
mathematical framework. Data associated with three significant exploits
involving vulnerabilities in phf, imap, and bind can all be modeled
using the formula C=I+S×√M where C is the cumulative count
of reported incidents, M is the time since the start of the exploit
cycle, and I and S are the regression coefficients determined by
analysis of the incident report data. Further analysis of two additional
exploits involving vulnerabilities in mountd and statd confirm the
model. We believe that the models will aid in predicting the severity of
subsequent vulnerability exploitations, based on the rate of early
incident reports
View citation and abstract |