Logo do repositório
 
Publicação

SecRush – New Generation Vulnerability Management Framework

datacite.subject.fosEngenharia e Tecnologia::Engenharia Eletrotécnica, Eletrónica e Informáticapt_PT
dc.contributor.advisorSá, Alan Oliveira de
dc.contributor.authorSantana, Miguel Tomás Cabrita
dc.date.accessioned2023-05-04T18:09:29Z
dc.date.available2023-05-04T18:09:29Z
dc.date.issued2023
dc.date.submitted2022
dc.descriptionTese de Mestrado, Segurança Informática, 2022, Universidade de Lisboa, Faculdade de Ciênciaspt_PT
dc.description.abstractVulnerabilities have been increasing over the years without signs of decreasing soon. With this ex ponential growth, it is important for organizations to define a vulnerability management plan to proceed with what should be done if they encounter a vulnerability. However, existing plans and metrics do not fit the current reality. Existing plans are not independent of vulnerability detection tools. The classifica tion systems currently used (the most common is CVSS) fail to provide information on the variation of risk that a particular vulnerability entails for the organization. As this is not constant, being exception ally high when there is a form of active exploitation, as well as its location in the network and business needs. SecRush presents itself as a new vulnerability management framework with a new risk-based vulnerability management process. It has a set of procedures inspired by agile methodologies to mitigate vulnerabilities and a new classification system - SecScore – able to provide a prioritization in context with the organization. SecScore varies its ranking through temporal factors (specific risk index depend ing on the organization’s risk appetite and the availability of an exploit) and environmental factors (asset visibility to the external network and importance of the asset to the organization’s mission). This project intends not only to contribute with a set of procedures independent of the security tools used but also to improve the currently existing classification systems for prioritization, which cannot adapt to the different contexts in which they are found.pt_PT
dc.identifier.tid203504372
dc.identifier.urihttp://hdl.handle.net/10451/57360
dc.language.isoengpt_PT
dc.subjectVulnerabilidadept_PT
dc.subjectGestão de Vulnerabilidadespt_PT
dc.subjectGestão de Vulnerabilidades Baseada em Riscopt_PT
dc.subjectCVSSpt_PT
dc.subjectTeses de mestrado - 2023pt_PT
dc.titleSecRush – New Generation Vulnerability Management Frameworkpt_PT
dc.typemaster thesis
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typemasterThesispt_PT
thesis.degree.nameMestrado em Segurança Informáticapt_PT

Ficheiros

Principais
A mostrar 1 - 2 de 2
A carregar...
Miniatura
Nome:
TM_Miguel_Santana.pdf
Tamanho:
1.14 MB
Formato:
Adobe Portable Document Format
Miniatura indisponível
Nome:
secscore-dataset.txt
Tamanho:
4.58 KB
Formato:
Plain Text
Licença
A mostrar 1 - 1 de 1
Miniatura indisponível
Nome:
license.txt
Tamanho:
1.2 KB
Formato:
Item-specific license agreed upon to submission
Descrição: