Electronic Thesis/Dissertation
 

Cards and Stacks: A Dynamic, Asset-Centric and Machine Learning-Enhanced Approach to Cyber Vulnerability Management

Open Access Deposited

Vulnerability management is a critical component of defensive cyber operations. However, there are several weaknesses with the current approaches to vulnerability management. First, it has become increasingly difficult to map known vulnerabilities to an organization's affected systems. The Common Vulnerabilities and Exposures (CVE) program has logged over 200,000 vulnerabilities since inception and that number is projected to continue to rise exponentially, making it challenging for records to contain complete or timely information. Second, organizations often do not know exactly what components make up their information systems and particularly the software products within those systems. This leads to two common questions related to vulnerability management: "are we affected?" and "where are we affected?" Third, with only an estimated 2% of reported vulnerabilities actually exploited by malicious actors, the current approach of scanning for every single vulnerability fails to prioritize critical ones and often produces a high number of irrelevant results. This "noise" often overwhelms human cyber analysts charged with triaging the findings and leads to missing the more important “signals”. To help address these challenges, the concept of a Software Bill of Materials (SBOM) has recently emerged as an important topic in cybersecurity in general and vulnerability management in particular. This concept has taken even more urgency after the President of the United States issued Executive Order 14028 on Improving the Nation's Cybersecurity, which mandates that software developers prepare and transmit SBOMs to vendors, customers and users. For the purposes of our research, we broadly define an IT asset as any IT resource that provides value to an organization’s business operations. We introduce the concept of an Asset Bill of Materials (ABOM) – an extension and generalization of the SBOM concept – as a method to describe all components of an IT asset. We present a novel "Cards and Stacks" model of an ABOM and propose a dynamic, asset-centric, machine learning-enhanced approach to vulnerability management based on the ABOM concept. We then use CVE data along with a sample ABOM to demonstrate how our approach can assist with the discovery of relevant vulnerability information about assets in a sample IT environment. Finally, we propose areas of future research on extending and enhancing our ABOM approach.

Author Language Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Shaaban_gwu_0075A_16837.pdf Shaaban_gwu_0075A_16837.pdf 2024-10-02 Open Access