[论文解读] Risky Business: Assessing Security with External Measurements
本文提出一种数据驱动的外部测量方法,通过分析网络层面的风险向量(如配置错误的TLS服务、公开的不安全协议以及点对点文件共享)并将其与实际的僵尸网络感染率相关联,客观评估组织安全风险。基于2015年对37,000家组织的32亿个网络测量数据,研究发现这些风险向量与僵尸网络流行率之间存在显著的统计相关性,其中点对点活动与318倍更高的感染浓度相关,提供了一种定量、非侵入性的传统审计替代方案。
Security practices in large organizations are notoriously difficult to assess. The challenge only increases when organizations turn to third parties to provide technology and business services, which typically require tight network integration and sharing of confidential data, potentially increasing the organization's attack surface. The security maturity of an organization describes how well it mitigates known risks and responds to new threats. Today, maturity is typically assessed with audits and questionnaires, which are difficult to quantify, lack objectivity, and may not reflect current threats. This paper demonstrates how external measurement of an organization can be used to assess the relative quality of security among organizations. Using a large dataset from BitSight(www.bitsight.com), a cybersecurity ratings company, containing 3.2 billion measurements spanning nearly 37,000 organizations collected during calendar year 2015, we show how per-organizational "risk vectors" can be constructed that may be related to an organization's overall security posture, or maturity. Using statistical analysis, we then study the correlation between the risk vectors and botnet infections. For example, we find that misconfigured TLS services, publicly available unsecured protocols, and the use of peer-to-peer file sharing correlate with organizations that have increased rates of botnet infections. We argue that the methodology used to identify these correlations can easily be applied to other data to provide a growing picture of organizational security using external measurement.
研究动机与目标
- 为解决传统主观自报安全评估(如审计和问卷)缺乏客观性且无法反映真实世界威胁的局限性。
- 开发一种基于外部可观测网络数据的定量、非侵入性方法,用于评估组织安全成熟度。
- 识别与实际安全事件(如僵尸网络感染)相关联的具体、可量化的风险向量,而非假设性漏洞。
- 证明对外部网络测量数据的统计分析可揭示不同类型组织在安全态势方面的有意义模式。
- 为第三方风险评估和外包及合作关系中的安全决策提供可扩展、数据驱动的框架。
提出的方法
- 通过严谨且独特的过程将IP地址空间映射到具体组织,以将网络事件与特定实体关联。
- 通过大规模互联网扫描测量外部风险向量,包括配置错误的TLS服务、公开可访问的不安全协议以及点对点文件共享。
- 使用外部可观测数据收集并归一化僵尸网络感染数据,按组织规模进行归一化处理,以支持跨组织比较。
- 应用线性回归和统计建模,量化不同组织中风险向量与僵尸网络感染流行率之间的关系。
- 按组织类型(如行业)进行分组,分析风险向量影响在不同组织类别中的差异。
- 使用2015年收集的近37,000家组织的32亿个网络事件数据集,训练并验证统计模型。
实验结果
研究问题
- RQ1外部网络风险向量(如配置错误的TLS服务)与实际僵尸网络感染率之间的相关性有多大?
- RQ2特定风险向量(如点对点文件共享或不安全协议)的影响在不同类型组织中如何变化?
- RQ3对外部、客观的网络行为测量能否比传统审计或问卷提供更准确、更定量的组织安全成熟度评估?
- RQ4可观测网络配置错误与僵尸网络感染在现实组织中的流行率之间关系的强度如何?
- RQ5某些风险向量是否在不同行业中持续预测更高的感染率,还是相关性仅限于特定行业?
主要发现
- 通过BitTorrent进行点对点文件共享的组织,其僵尸网络感染浓度平均比无此类活动的组织高出318倍。
- 配置错误的TLS服务和公开可用的不安全协议在多种组织类型中均与僵尸网络感染率的增加存在统计相关性。
- 即使在按组织规模归一化后,风险向量与僵尸网络感染之间的相关性依然显著,表明二者关系具有稳健性。
- 尽管三类风险向量在整体上均与感染相关,但其对不同行业的个体影响存在显著差异,部分向量仅在特定行业中具有显著影响。
- 90%的组织感染率较低(每12名员工少于1次感染),但感染水平跨度达多个数量级,凸显安全态势的极端差异性。
- 本研究证明,对外部网络测量数据的统计分析可识别出有意义且可量化的风险模式,而无需依赖自报数据或侵入性内部审计。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。