VCPEC: Vulnerability correlation analysis based on privilege escalation and coritivity theory

Xuefei Wang, Rui Ma, Donghai Tian, Xiajing Wang

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Citations (Scopus)

Abstract

Vulnerability correlation analysis has become a key technique in the field of vulnerability analysis, which effectively addresses the limitation of only analyzing an isolated vulnerability. Even though the existing techniques have demonstrated their effectiveness in assessing the complex relationship between the vulnerabilities, they remain limited in accurately locating critical vulnerabilities. To overcome this issue, we design a vulnerability correlation analysis method, named VCPEC, to discover critical vulnerabilities using extended coritivity theory towards a novel privilege model. The key idea is to construct a vulnerability correlation graph (VCG) according to the system privilege grading strategy and the vulnerability privilege escalation paths, reducing the complexity in the graph. Then use the extended coritivity theory to calculate the core of the VCG, that means the critical vulnerabilities can be further recognized. Thus, by repairing critical vulnerabilities to achieve efficient protection of target system, saving the cost of repairing vulnerabilities. We design and perform experiments to verify the feasibility and efficiency of VCPEC in real-world software systems. And the results show that VCPEC can accurately locate critical vulnerabilities.

Original languageEnglish
Title of host publicationICCNS 2020 - 2020 10th International Conference on Communication and Network Security
PublisherAssociation for Computing Machinery
Pages99-108
Number of pages10
ISBN (Electronic)9781450389037
DOIs
Publication statusPublished - 27 Nov 2020
Event10th International Conference on Communication and Network Security, ICCNS 2020 - Virtual, Online, Japan
Duration: 27 Nov 202029 Nov 2020

Publication series

NameACM International Conference Proceeding Series

Conference

Conference10th International Conference on Communication and Network Security, ICCNS 2020
Country/TerritoryJapan
CityVirtual, Online
Period27/11/2029/11/20

Keywords

  • Coritivity theory
  • Privilege escalation
  • Vulnerability correlation analysis

Fingerprint

Dive into the research topics of 'VCPEC: Vulnerability correlation analysis based on privilege escalation and coritivity theory'. Together they form a unique fingerprint.

Cite this