<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2016.74022</article-id><article-id pub-id-type="publisher-id">JIS-68736</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Stochastic Modelling of Vulnerability Life Cycle and Security Risk Evaluation
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Sasith</surname><given-names>M. Rajasooriya</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Chris</surname><given-names>P. Tsokos</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Pubudu</surname><given-names>Kalpani Kaluarachchi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Department of Mathematics and Statistics, University of South Florida, Tampa, Florida, USA</addr-line></aff><pub-date pub-type="epub"><day>07</day><month>07</month><year>2016</year></pub-date><volume>07</volume><issue>04</issue><fpage>269</fpage><lpage>279</lpage><history><date date-type="received"><day>20</day>	<month>June</month>	<year>2016</year></date><date date-type="rev-recd"><day>accepted</day>	<month>18</month>	<year>July</year>	</date><date date-type="accepted"><day>21</day>	<month>July</month>	<year>2016</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
  The objective of the present study is to propose a risk evaluation statistical model for a given vulnerability by examining the Vulnerability Life Cycle and the CVSS score. Having a better understanding of the behavior of vulnerability with respect to time will give us a great advantage. Such understanding will help us to avoid exploitations and introduce patches for a particular vulnerability before the attacker takes the advantage. Utilizing the proposed model one can identify the risk factor of a specific vulnerability being exploited as a function of time. Measuring of the risk factor of a given vulnerability will also help to improve the security level of software and to make appropriate decisions to patch the vulnerability before an exploitation takes place.
 
</p></abstract><kwd-group><kwd>Stochastic Modelling</kwd><kwd> Security</kwd><kwd> Risk Evaluation</kwd><kwd> Vulnerability Life Cycle</kwd><kwd> Risk Factor</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>In a recent study, “Cybersecurity: A Statistical Predictive Model for the Expected Path Length” (Journal of Information Security, 2016, 7, 112-128 [<xref ref-type="bibr" rid="scirp.68736-ref1">1</xref>] ), we introduced a method by which one can predict the Expected Path Length, the expected number of steps the attacker will take, starting from the initial state to achieve his target. In the present study, we propose a method using Markov chain to understand the Vulnerability Life Cycle and Security Risk behavior.</p><p>Any identified vulnerability [<xref ref-type="bibr" rid="scirp.68736-ref2">2</xref>] is hazardous to a security system and makes the system susceptible to be exploited until it is well patched. Therefore, we believe it is very important to know how to deal with a vulnerability behavior throughout its different stages. “Vulnerability Life Cycle” [<xref ref-type="bibr" rid="scirp.68736-ref3">3</xref>] would certainly help us to better understand the vulnerability and its behavior in a security system with respect to time. There are a number of ways to present the life cycle of a particular vulnerability. However, all these different introductions have several important stages in common. The level of the risk associated with different stages of vulnerability should be different indeed and need to be estimated.</p><p>However, measuring of such a “risk factor” [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] and obtaining a probabilistic estimate are certainly a challenge given the lack of data resources. If we have a method developed to measure the risk level associated with a particular vulnerability at a certain time or stage, it will help the users and organizations to act accordingly with well-defined priorities. Then the users and organizations can make sure adequate attention, resources and security intellects are employed to address such a risk and proper fixing steps are taken before it is exploited. One of the main objectives we have is to obtain a statistical model that can give us the probability of a vulnerability being exploited or patched at a given time. In this study, we use the well-known theory of Markov Chain Process to develop such a model.</p></sec><sec id="s2"><title>2. Vulnerability and Vulnerability Life Cycle</title><p>In this section we will explain basic concept of Vulnerability, Vulnerability Life Cycle and related technical terms to make it easier to understand later sections.</p><p>Microsoft Security Response Center (MSRC) defines the term Vulnerability [<xref ref-type="bibr" rid="scirp.68736-ref2">2</xref>] - [<xref ref-type="bibr" rid="scirp.68736-ref6">6</xref>] as follows.</p><p>“A security vulnerability is a weakness in a product that could allow an attacker to compromise the integrity, availability, or confidentiality of that product”.</p><p>We understand that vulnerability could be derived by investigating the various weaknesses of an implemented security system. With a weakness in a custom design software, a vulnerability can come to effect in authentication protocols, software reliability and system process, Hardware management and Networking among others.</p><sec id="s2_1"><title>2.1. Common Vulnerability Scoring System (CVSS)</title><p>Common Vulnerability Scoring System (CVSS) [<xref ref-type="bibr" rid="scirp.68736-ref7">7</xref>] is a commonly used and freely available standard for assessing the magnitude of Information system Vulnerabilities. CVSS gives a score for each vulnerability scaling from 0 to 10 based on several factors. National Vulnerability Database (NVD) provides CVSS score and updates continuously with new vulnerabilities are found. CVSS score is calculated using three main matrices named, Base Matric, Temporal Metric and Environmental Metric. However, NVD data base provides us with the Base Metric Scores for the Vulnerability only because the Temporal and Environmental Scores are varied on other factors related to organization that uses the computer system. The Base score for more than 75,000 different vulnerabilities are calculated using 6 different Matrices. It is managed by the Forum of Incident Response and Security Teams (FIRST). CVSS establishes a standard measure of how much concern a vulnerability warrants, compared to other vulnerabilities, so efforts can be prioritized. The scores range from 0 to 10. Vulnerabilities with a base score in the range of 7.0 - 10.0 are considered “High”. Those in the ranges of 4.0 - 6.9, and 0 - 3.9 are considered as “Medium” and “Low” respectively.</p></sec><sec id="s2_2"><title>2.2. Stages of Vulnerability Life Cycle</title><p>The Life Cycle of a Vulnerability [<xref ref-type="bibr" rid="scirp.68736-ref2">2</xref>] - [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] can be introduced with different stages that a vulnerability passes through. We shall discuss specific stages that are commonly identified in a given situation. Commonly identified stages are involved with the events such as the Birth (Pre-discovery Stage), Discovery, Disclosure, Availability for Patching and Availability for Exploiting [<xref ref-type="bibr" rid="scirp.68736-ref8">8</xref>] - [<xref ref-type="bibr" rid="scirp.68736-ref10">10</xref>] .</p><p><xref ref-type="fig" rid="fig1">Figure 1</xref> illustrates the life cycle of vulnerability showing key stages to be discussed.</p><p>Birth (Pre-Discovery):</p><p>The birth of vulnerability occurs at the development of a software, mostly due to a weakness or a mistake in coding of the software. At this stage the vulnerability is not yet discovered or exploited. In a well-developed software package where its reliability has been identified, one can identify the probability of the birth of the problem.</p><p>Discovery:</p><p>Vulnerability is said to be discovered once someone identifies the flaw in the software. It is possible that the vulnerability is discovered by the system developers themselves, skilled legitimate users or by the attackers also. If the vulnerability is discovered internally or by white hackers, (who are making breaking attempts on a system to identify the flaws and vulnerabilities with good intentions of helping them to be patched so that the system security is strengthened) it will be notified to be fixed as soon as possible. But, if a black hacker discovers a vulnerability it is possible that he or she will try to exploit it, or sell in the black market or distribute it among hackers to be exploited.</p><p>It should be noted here that while vulnerabilities could actually exist prior to the discovery, until it is discovered, it is not a potential security risk. “Time of the discovery” is the earliest time that vulnerability is identified. In a vulnerability life cycle the “time of discovery” is an important and critical event. Exact discovery time might not be published or disclosed to the public due to the other risks that could be associated with vulnerability. However, in general after the “disclosure” of vulnerability, public may know the time of discovery subject to security risk review.</p><p>We would like to mention here that in developing our statistical model, we consider only “pre-exploit discovery”. There are rare chances that a discovery of vulnerability could occur after it is actually exploited. As an example, an attacker could run an exploit attempt aiming for a particular vulnerability but, the exploit instead break the intended system through another unidentified or undiscovered vulnerability at that time. While intending to address and incorporate such rare occurrences in our future research, in the present study we will consider vulnerabilities that we discovered before being exploited.</p><p>Disclosure:</p><p>Once a vulnerability is discovered, it is subject to be disclosed. Disclosure could take place in different ways based on the system design, authentication and who discovered it. However, “disclosure” in widely accepted form in the information security means the event that a particular vulnerability is made known to public through relevant and appropriate channels. Definition for the disclosure of vulnerability is however presented differently by different individuals.</p><p>In general, public disclosure of a vulnerability is based on several principles. The “availability of access” to the vulnerability information for the public is one such important principle. Another such important principle is “validity of information”. Validity of information principle is to ensure the user’s ability to use that information, assess the risk and take security measures. Also, the “independence of information channels” is also considered to be important to avoid any bias and interferences from organizational bodies including the vendor.</p><p>Scripting (Exploiting) and Exploit Availability:</p><p>A Vulnerability enters to the stage of “exploit availability” from the earliest time that an exploit program of code is available. Once the exploits are available even low skilled crackers (or in other words a black hat hacker) could be capable of exploiting the vulnerability. As we mentioned earlier, there are some occurrences that the exploit could happen even before the vulnerability is discovered. However in the present study we consider the modelling of Vulnerability Life Cycles with exploit availability occurs only after the discovery.</p><p>Patch Availability and Death: (Patched)</p><p>Patch is a software solution that the vendor or developer release to provide necessary protection from possible exploits of the vulnerability. Patch will act against possible exploit codes or attacking attempts for a vulnerability and protect the system and ensure the integrity. The vulnerability dies when one applies a security patch to all the vulnerable systems.</p><p>When a White Hat Researcher discovers a vulnerability, the next transition is likely to be the internal disclosure leading to patch development. On the other hand, if a Black Hat Hacker discovers a vulnerability, the next transition could be an exploit or internal disclosure to his underground community. Some active black hats might develop scripts that exploit the vulnerability. <xref ref-type="fig" rid="fig1">Figure 1</xref> illustrates the process of the above discussion.</p></sec></sec><sec id="s3"><title>3. Methodology</title><sec id="s3_1"><title>3.1. Markov Chain and Transition Probabilities</title><p>A discrete type stochastic process <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x7.png" xlink:type="simple"/></inline-formula> is called a Markov chain [<xref ref-type="bibr" rid="scirp.68736-ref11">11</xref>] if for any sequence <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x8.png" xlink:type="simple"/></inline-formula> of states, the next state depends only on the current state and not on the sequence of events that preceded it, which is called the Markov property. Mathematically, we can write this property as presented</p><fig id="fig1"  position="float"><label><xref ref-type="fig" rid="fig1">Figure 1</xref></label><caption><title> The life cycle of vulnerability [<xref ref-type="bibr" rid="scirp.68736-ref3">3</xref>] </title></caption><graphic mimetype="image"   position="float"  xlink:type="simple"  xlink:href="http://html.scirp.org/file/5-7800396x9.png"/></fig><p>in Equation (1) below.</p><disp-formula id="scirp.68736-formula770"><label>(1)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x10.png"  xlink:type="simple"/></disp-formula><p>We will also make the assumption that the transition probabilities <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x11.png" xlink:type="simple"/></inline-formula> do not depend on time. This is called time homogeneity. The transition probabilities (P<sub>i</sub><sub>,j</sub>)for Markov chain can be defined as follows.</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x12.png" xlink:type="simple"/></inline-formula>,</p><p>That is the probability of being in state j given that we were in state i.</p><p>The transition matrix P of the Markov chain is the N &#215; N matrix whose <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x13.png" xlink:type="simple"/></inline-formula> entry <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x14.png" xlink:type="simple"/></inline-formula> satisfied the following properties.</p><disp-formula id="scirp.68736-formula771"><label>(2)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x15.png"  xlink:type="simple"/></disp-formula><p>and</p><disp-formula id="scirp.68736-formula772"><label>(3)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x16.png"  xlink:type="simple"/></disp-formula><p>Any matrix satisfying Equations ((2) and (3)) above is a Transition Probability Matrix for a Markov chain.</p><p>To simulate a Markov chain, we need its stochastic matrix P and an initial probability distribution π<sub>o</sub>.</p><p>Here, we shall simulate an N-state Markov chain (X; P; π<sub>0</sub>) for<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x17.png" xlink:type="simple"/></inline-formula>, time periods. Let X be a vector of possible state values from sample realizations of the chain. Iterating on the Markov chain we will produce a sample path {X<sub>N</sub>} where for each N, X<sub>N</sub> &#206; X. When writing a simulation program this is about using uniformly distributed U [0, 1] random numbers to obtain the corrected probability distribution in every step.</p></sec><sec id="s3_2"><title>3.2. Transient States</title><p>Let P be the probability transition matrix [<xref ref-type="bibr" rid="scirp.68736-ref11">11</xref>] for Markov chain X<sub>n</sub>. A “state i” is called transient state if with probability 1 the chain visits i only a finite number of times. Let Q be the sub matrix of P which includes only the rows and columns for the transient states. The transition matrix for an absorbing Markov chain has the following canonical form.</p><disp-formula id="scirp.68736-formula773"><label>. (4)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x18.png"  xlink:type="simple"/></disp-formula><p>Here in Equation (4), P is the transition matrix, Q is the matrix of transient states, R is the matrix of absorbing states and I is the identity matrix.</p><p>The matrix P represents the transition probability matrix of the absorbing Markov chain. In an absorbing Markov chain the probability that the chain will be absorbed is always 1. Hence, we have</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x19.png" xlink:type="simple"/></inline-formula>.</p><p>Thus, is it implies that all the eigenvalues of Q have absolute values strictly less than 1. Hence, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x20.png" xlink:type="simple"/></inline-formula>is an invertible matrix and there is no problem in defining the matrix</p><disp-formula id="scirp.68736-formula774"><label>. (5)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x21.png"  xlink:type="simple"/></disp-formula><p>This matrix M in Equation (5) is called the Fundamental Matrix of P. Let i be a transient state and consider<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x22.png" xlink:type="simple"/></inline-formula>, the total number of visits to state i. Then we can show that the expected number of visits to state i starting at state j is given by <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x23.png" xlink:type="simple"/></inline-formula> the <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x22.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x23.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x24.png" xlink:type="simple"/></inline-formula> entry of the matrix M. <sub> </sub></p><p>Therefore, if we want to compute the expected number of steps until the chain enters a recurrent class, assuming starting at state j, we need only sum <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x25.png" xlink:type="simple"/></inline-formula> over all transient states i.</p></sec></sec><sec id="s4"><title>4. Vulnerability Life Cycle Analysis Method</title><sec id="s4_1"><title>4.1. Vulnerability Life Cycle Graph</title><p>The core component of the Vulnerability Life Cycle Analysis method we propose here is the Life Cycle Graph [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] . When we draw a Life Cycle Graph for a given vulnerability it has several nodes which represent the Vulnerability Life Cycle stages. We can assign a possible probability to reach each state by examining the properties of a specific vulnerability. Also, a Life Cycle Graph has two absorbing states [<xref ref-type="bibr" rid="scirp.68736-ref11">11</xref>] - [<xref ref-type="bibr" rid="scirp.68736-ref13">13</xref>] that are named “Patched state” and “Exploited state” [<xref ref-type="bibr" rid="scirp.68736-ref3">3</xref>] [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] . Therefore, this allows us to model the Life Cycle Graph as an absorbing Markov chain.</p><p>The Markov Model Approach to Vulnerability Life Cycle we develop is given in <xref ref-type="fig" rid="fig2">Figure 2</xref>. In this figure, we present a Markov approach of Vulnerability Life Cycle with five states. It should be noted that the states three and five are absorbing states of this Life Cycle Graph as there are no out flaws from those states.</p><p>We define,</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x26.png" xlink:type="simple"/></inline-formula>= the probability of transferring state i to state j.</p><p>In actual situations the probability of discovering a vulnerability can be assumed very small. Therefore, for <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x27.png" xlink:type="simple"/></inline-formula> we can assign a small value. Then we assigned probabilities to<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x27.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x28.png" xlink:type="simple"/></inline-formula>, accordingly.</p><p>Using these transition probabilities we can derive the absorbing transition probability matrix for a Vulnerability Life Cycle, which follows the properties defined under Markov Chain Transformation Probability Method.</p></sec><sec id="s4_2"><title>4.2. Transition Matrix for Vulnerability Life Cycle</title><p>Thus, we can write the transition probability matrix for vulnerability life cycle as follows.</p><fig id="fig2"  position="float"><label><xref ref-type="fig" rid="fig2">Figure 2</xref></label><caption><title> Markov model approach to vulnerability life cycle with five states</title></caption><graphic mimetype="image"   position="float"  xlink:type="simple"  xlink:href="http://html.scirp.org/file/5-7800396x29.png"/></fig><disp-formula id="scirp.68736-formula775"><graphic  xlink:href="http://html.scirp.org/file/5-7800396x30.png"  xlink:type="simple"/></disp-formula><p>where,</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x31.png" xlink:type="simple"/></inline-formula>- Probability that the system is in state i at time t.</p><p>For <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x32.png" xlink:type="simple"/></inline-formula> we have</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x33.png" xlink:type="simple"/></inline-formula>, Probability that the system is in State 1 at the beginning (<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x33.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x34.png" xlink:type="simple"/></inline-formula>).</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x35.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x35.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x36.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x35.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x36.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x37.png" xlink:type="simple"/></inline-formula>,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x35.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x36.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x37.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x38.png" xlink:type="simple"/></inline-formula>.</p><p>Therefore, the initial probability can be given as<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x39.png" xlink:type="simple"/></inline-formula>, that is, the probabilities of each state of the Vulnerability Life Cycle initially. It is clear that, the “State 1” (Not Discovered) with probability of one represents that at the initial time (for t = 0), the Vulnerability is not yet been discovered and therefore the probabilities for all others stages are zero.</p><p>We can assign some reasonable values to<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x40.png" xlink:type="simple"/></inline-formula>’ s and create the transformation matrix P as follows. As an example, if we consider a time intervals of days, for probabilities of each stage to a specific vulnerability can be derived using the Markov process as follows.</p><p>For<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x41.png" xlink:type="simple"/></inline-formula>, we have</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x42.png" xlink:type="simple"/></inline-formula>.</p><p>For<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x43.png" xlink:type="simple"/></inline-formula>, results in</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x44.png" xlink:type="simple"/></inline-formula>.</p><p>For<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x45.png" xlink:type="simple"/></inline-formula>, we can write</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x46.png" xlink:type="simple"/></inline-formula>,</p><p>And thus, for = n, we have</p><p><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x47.png" xlink:type="simple"/></inline-formula>.</p><p>Using this method, we can find the pattern of probability that is changing with time and is related to each “state” and then to work on finding the statistical model that can fit the vulnerability life cycle.</p><p>For<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x49.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x49.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x50.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x49.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x50.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x51.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x49.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x50.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x51.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x52.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x48.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x49.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x50.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x51.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x52.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x53.png" xlink:type="simple"/></inline-formula>transition probability matrix can be written as follows:</p><disp-formula id="scirp.68736-formula776"><graphic  xlink:href="http://html.scirp.org/file/5-7800396x54.png"  xlink:type="simple"/></disp-formula><p>As we execute this algorithm, the stationarity was reached (considering to 4 decimal digits) at<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x55.png" xlink:type="simple"/></inline-formula>, that is at<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x55.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x56.png" xlink:type="simple"/></inline-formula>, we can find the minimum number of steps so that the vulnerability reaches its absorbing states and the resulting vector of probabilities for each of the states is obtained as follows. As the row vector presents, the transition probabilities are completely absorbed into the two absorbing states which gives the probability of the vulnerability that is being exploited and the probability of the vulnerability will be patched. All other states have reached the probability of zero. That is,</p><disp-formula id="scirp.68736-formula777"><graphic  xlink:href="http://html.scirp.org/file/5-7800396x57.png"  xlink:type="simple"/></disp-formula><p>The following figures illustrate the behavior of the probabilities as a function of time with respect to the different states. For states one, three, four and five taking initial probabilities as mentioned above, the behavior as a function of time is graphed. For states one and three the probability of “Not-discovered” and “Disclosed not patched” respectively, decreases with respect to time and approach zero eventually.</p><p><xref ref-type="fig" rid="fig3">Figure 3</xref> presents the behavior of the probability of each state based on the initial probabilities we assigned. It is clear that the probability of being in the state 1 decreases and approach zero eventually. This indicates that the probability of a vulnerability being “Not-discovered” over the time is decreasing and eventually reaches zero at the time of the “discovery” (<xref ref-type="fig" rid="fig3">Figure 3</xref>(a)). Once a vulnerability is discovered, the probability of being “Exploited” over time indeed increases. And as the system security activities also will immediately take place, the probability of being “Patched” also increases. This behavior is presented in <xref ref-type="fig" rid="fig3">Figure 3</xref>(b) and <xref ref-type="fig" rid="fig3">Figure 3</xref>(d), respectively. There is also a time gap between the disclosure and patching of the vulnerability. Initially, the probability of the vulnerability being “Disclosed not patched” will rise for a very short period of time then will decrease eventually as this is not an absorbing state in the life cycle.</p><p>For a better understanding, comparison and to have a more generalize observation we proceed to check the behavior of these probabilities over the time with different probability assigned values. We change λ<sub>1</sub> values and compare the probability changes in each state with time. The following graphs, illustrate the behavior of each state for λ<sub>1</sub> = 0.1, 0.2, 0.4, 0.5 and 0.7. <xref ref-type="fig" rid="fig4">Figure 4</xref>(a) and <xref ref-type="fig" rid="fig4">Figure 4</xref>(b) represent those behaviors graphically. Each graph presents the behavior of the probability of being in that “state” of the life cycle over time. It is interesting to observe that the initial probability that we assign for λ<sub>1</sub> did not really affect much on the behavior of the probability over time.</p><p>However, it is important to note that a vulnerability with a higher initial probability of being “discovered” will go to stationarity faster than to those with a lower initial probability of being “discovered”. This is observable from the graphs labeled “Probability of being Exploited as a function of time” and “Probability of being Patched as a function of time” in <xref ref-type="fig" rid="fig4">Figure 4</xref>(a) and <xref ref-type="fig" rid="fig4">Figure 4</xref>(b) respectively.</p></sec></sec><sec id="s5"><title>5. The Risk Factor and Parametric Model</title><sec id="s5_1"><title>5.1. Introducing the Risk Factor and Evaluating the Risk Level as a Function of Time</title><p>Vulnerabilities which have been discovered but not patched represents a security risk [<xref ref-type="bibr" rid="scirp.68736-ref14">14</xref>] - [<xref ref-type="bibr" rid="scirp.68736-ref16">16</xref>] which can lead to considerable financial damage or loss of reputation (credibility).Therefore estimating the risk is very important and in the present study we introduce a method to evaluate the risk level [<xref ref-type="bibr" rid="scirp.68736-ref3">3</xref>] [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] of discovered vulnerabilities [<xref ref-type="bibr" rid="scirp.68736-ref16">16</xref>] .</p><p>By examining <xref ref-type="fig" rid="fig3">Figure 3</xref> we discussed above, that is related to the state “Exploited” in the Vulnerability Life Cycle, we can clearly see the pattern of exploitability as a function of time. As a function of time, the probability</p><fig id="fig3"  position="float"><label><xref ref-type="fig" rid="fig3">Figure 3</xref></label><caption><title> Behavior of the probability of different states as a function of time</title></caption><graphic mimetype="image"   position="float"  xlink:type="simple"  xlink:href="http://html.scirp.org/file/5-7800396x58.png"/></fig><fig id="fig4"  position="float"><label><xref ref-type="fig" rid="fig4">Figure 4</xref></label><caption><title> (a) Comparison of the behavior of the probabilities of different states with different initial probabilities for the discovery; (b) Comparison of the behavior of the probabilities of different states with different initial probabilities for the discovery</title></caption><graphic mimetype="image"   position="float"  xlink:type="simple"  xlink:href="http://html.scirp.org/file/5-7800396x59.png"/></fig><p>of being exploited increases significantly up to some stage and then eventually become stable.</p><p>To evaluate the risk factor [<xref ref-type="bibr" rid="scirp.68736-ref4">4</xref>] of exploiting with respect to the time we consider the changes in the probability and also the CVSS score of a specific vulnerability. We explore the use of the CVSS vulnerability metrics which are publically available and are being used for ranking the strength of all vulnerabilities.</p><p>Let’s proceed to define the risk factor as follows:</p><p>Let, v<sub>i</sub> be any specific vulnerability. Then,</p><disp-formula id="scirp.68736-formula778"><label>(6)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x60.png"  xlink:type="simple"/></disp-formula><p>We shall use this definition of the Risk Factor in developing our proposed statistical model to evaluate the risk behavior.</p></sec><sec id="s5_2"><title>5.2. Development of a Parametric Model to Predict the Probability of Vulnerability Being Exploited</title><p>To accomplish our objective, we developed two statistical models where the response variable Y is the probability of being exploited and is driven by the attributable variable , the time. At first, for statistical accuracy to homogenize the variance we filtered the data using natural logarithm,<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x61.png" xlink:type="simple"/></inline-formula>. For the second model, to obtain a better fit to the data we introduce a term with an inverse transformation in addition to the filter using the natural logarithm.</p><p>Thus, the proposed final forms of the statistical model to estimate the probability of being exploited at time t is given in the table below.</p><p>For<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x63.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x63.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x64.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x63.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x64.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x65.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x63.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x64.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x65.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x66.png" xlink:type="simple"/></inline-formula>, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x62.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x63.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x64.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x65.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x66.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x67.png" xlink:type="simple"/></inline-formula>values we proposed a model to predict the probability at different time intervals as follows.</p><p>As an example, let’s take a specific vulnerability labeled as CVE-2016-0467. This has CVSS Base score 4.00, which categorized as medium score with “Impact sub score: 2.9” and “Exploitability sub score: 8.0”. For This vulnerability we can measure risk as follows.</p><disp-formula id="scirp.68736-formula779"><label>(7)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x68.png"  xlink:type="simple"/></disp-formula><p>Using equation (7) above, we can predict the risk factor of specific vulnerability at any time interval.</p><p>This is an excellent model that gives us an <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x69.png" xlink:type="simple"/></inline-formula> of 0.8526 and <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x69.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x70.png" xlink:type="simple"/></inline-formula> of 0.8507. The<inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x69.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x70.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x71.png" xlink:type="simple"/></inline-formula>, named Coefficient of Determination tells us how much can the change in the response variable be explained and predicted by the attributable variables of the model and considered as the key criterion in evaluating the quality of a model. In other words, <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x69.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x70.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x71.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x72.png" xlink:type="simple"/></inline-formula>equals to the ratio of the Sum of Squares of the Regression to the Total Sum of Squares. That is,</p><disp-formula id="scirp.68736-formula780"><label>. (8)</label><graphic position="anchor" xlink:href="http://html.scirp.org/file/5-7800396x73.png"  xlink:type="simple"/></disp-formula><p>Let’s consider an example to illustrate these two models further. For the given values for <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x74.png" xlink:type="simple"/></inline-formula> to <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x74.png" xlink:type="simple"/></inline-formula><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x75.png" xlink:type="simple"/></inline-formula> given above, consider the values of the response variable Y (Probability of being exploited) at several values of time t. <xref ref-type="table" rid="table1">Table 1</xref> presents two model equations we have developed with respective R<sup>2</sup> values. <xref ref-type="table" rid="table2">Table 2</xref> illustrates several results obtained and we can obtain the Sum of Squared Error for the model using such data.</p><p>While the second model qualify to be much better as <inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x76.png" xlink:type="simple"/></inline-formula> is higher compared to the first model as we mentioned previously, it should be noted here that our comparison with respect to the probability of being exploited is in comparison with the probability obtained from our transition metrics for a particular time t.</p><p>We can generate such set of models for different vulnerabilities involving different CVSS score and improve further for predicting probabilities with respect to critical stages in Vulnerability Life Cycle of a particular Vulnerability.</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Proposed models for estimating the probability of being exploited at time t</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Model</th><th align="center" valign="middle" ><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x77.png" xlink:type="simple"/></inline-formula></th><th align="center" valign="middle" ><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x78.png" xlink:type="simple"/></inline-formula></th></tr></thead><tr><td align="center" valign="middle" ><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x79.png" xlink:type="simple"/></inline-formula></td><td align="center" valign="middle" >0.7544</td><td align="center" valign="middle" >0.7528</td></tr><tr><td align="center" valign="middle" ><inline-formula><inline-graphic xlink:href="http://html.scirp.org/file/5-7800396x80.png" xlink:type="simple"/></inline-formula></td><td align="center" valign="middle" >0.8526</td><td align="center" valign="middle" >0.8507</td></tr></tbody></table></table-wrap><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Probabilities estimated using two models for several values of time, t</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >t</th><th align="center" valign="middle" >Model 1 Estimate</th><th align="center" valign="middle" >Model 2 Estimate</th></tr></thead><tr><td align="center" valign="middle" >1</td><td align="center" valign="middle" >0.0868</td><td align="center" valign="middle" >−0.09469</td></tr><tr><td align="center" valign="middle" >2</td><td align="center" valign="middle" >0.123051598</td><td align="center" valign="middle" >0.063851598</td></tr><tr><td align="center" valign="middle" >3</td><td align="center" valign="middle" >0.144257423</td><td align="center" valign="middle" >0.122384761</td></tr><tr><td align="center" valign="middle" >18</td><td align="center" valign="middle" >0.237966443</td><td align="center" valign="middle" >0.256321119</td></tr><tr><td align="center" valign="middle" >19</td><td align="center" valign="middle" >0.240794159</td><td align="center" valign="middle" >0.258878711</td></tr><tr><td align="center" valign="middle" >20</td><td align="center" valign="middle" >0.243476798</td><td align="center" valign="middle" >0.261266372</td></tr><tr><td align="center" valign="middle" >28</td><td align="center" valign="middle" >0.261074296</td><td align="center" valign="middle" >0.27611951</td></tr><tr><td align="center" valign="middle" >29</td><td align="center" valign="middle" >0.262909572</td><td align="center" valign="middle" >0.277598327</td></tr><tr><td align="center" valign="middle" >30</td><td align="center" valign="middle" >0.264682623</td><td align="center" valign="middle" >0.279016035</td></tr><tr><td align="center" valign="middle" >58</td><td align="center" valign="middle" >0.299161169</td><td align="center" valign="middle" >0.304882684</td></tr><tr><td align="center" valign="middle" >59</td><td align="center" valign="middle" >0.300055208</td><td align="center" valign="middle" >0.305519416</td></tr><tr><td align="center" valign="middle" >60</td><td align="center" valign="middle" >0.300934221</td><td align="center" valign="middle" >0.306144133</td></tr><tr><td align="center" valign="middle" >88</td><td align="center" valign="middle" >0.320964715</td><td align="center" valign="middle" >0.320071521</td></tr><tr><td align="center" valign="middle" >89</td><td align="center" valign="middle" >0.321555682</td><td align="center" valign="middle" >0.320474602</td></tr><tr><td align="center" valign="middle" >90</td><td align="center" valign="middle" >0.322140046</td><td align="center" valign="middle" >0.320872795</td></tr><tr><td align="center" valign="middle" >98</td><td align="center" valign="middle" >0.326593799</td><td align="center" valign="middle" >0.323895552</td></tr><tr><td align="center" valign="middle" >99</td><td align="center" valign="middle" >0.327124768</td><td align="center" valign="middle" >0.324254543</td></tr><tr><td align="center" valign="middle" >100</td><td align="center" valign="middle" >0.327650401</td><td align="center" valign="middle" >0.324609648</td></tr></tbody></table></table-wrap></sec></sec><sec id="s6"><title>6. Conclusions</title><p>Using of the Markov Model Approach to Vulnerability Life Cycle, we can have a better understanding of the behavior of vulnerability as a function of time. In the present study, we have developed a successful statistical model to estimate the probability of being in a certain stage of a particular vulnerability in its life cycle. In Sections 3 and 4, we have presented our methodology of using the Markov Approach and Life Cycle Graph Analysis. This analysis with the application of Markov Chain Theory gave us the basis for calculating estimates for probabilities for different stages of a life cycle of the vulnerability considered.</p><p>Further in Section 5, we have also developed a “RISK FACTOR”, and statistical models to estimate the risk for a particular vulnerability being exploited combining our methodology with the exploitability score given in the CVSS score. Using the developed method, we can evaluate the risk level of a particular vulnerability at a certain time.</p><p>These developments ensure us with a great advantage in taking measures to avoid exploitations and introduce patches for the vulnerability before attacker takes the advantage of that particular vulnerability.</p></sec><sec id="s7"><title>Cite this paper</title><p>Sasith M. Rajasooriya,Chris P. Tsokos,Pubudu Kalpani Kaluarachchi, (2016) Stochastic Modelling of Vulnerability Life Cycle and Security Risk Evaluation. Journal of Information Security,07,269-279. doi: 10.4236/jis.2016.74022</p></sec><sec id="s8"><title>NOTES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.68736-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Kaluarachchi, P.K., Tsokos, C.P. and Rajasooriya, S.M. (2016) Cybersecurity: A Statistical Predictive Model for the Expected Path Length. Journal of information Security, 7, 112-128. http://dx.doi.org/10.4236/jis.2016.73008</mixed-citation></ref><ref id="scirp.68736-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">(2016) NVD, National Vulnerability Database. http://nvd.nist.gov/</mixed-citation></ref><ref id="scirp.68736-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Frei, S. (2009) Security Econometrics: The Dynamics of (IN) Security. PhD Dissertation, ETH, Zurich.</mixed-citation></ref><ref id="scirp.68736-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">Joh, H. and Malaiya, Y.K. (2010) A Framework for Software Security Risk Evaluation Using the Vulnerability Lifecycle and CVSS Metrics. Proceedings of the International Workshop on Risk and Trust in Extended Enterprises, November 2010, 430-434.</mixed-citation></ref><ref id="scirp.68736-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Kijsanayothin, P. (2010) Network Security Modeling with Intelligent and Complexity Analysis. PhD Dissertation, Texas Tech University, Lubbock.</mixed-citation></ref><ref id="scirp.68736-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H., Malaiya, Y.K. and Ray, I. (2007) Measuring, Analyzing and Predicting Security Vulnerabilities in Software Systems. Computers and Security Journal, 26, 219-228. http://dx.doi.org/10.1016/j.cose.2006.10.002</mixed-citation></ref><ref id="scirp.68736-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Schiffman, M. (2014) Common Vulnerability Scoring System (CVSS). http://www.first.org/cvss/</mixed-citation></ref><ref id="scirp.68736-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Noel, S., Jacobs, M., Kalapa, P. and Jajodia, S. (2005) Multiple Coordinated Views for Network Attack Graphs. VIZSEC’05: Proceedings of the IEEE Workshops on Visualization for Computer Security, Minneapolis, October 2005, 99-106. http://dx.doi.org/10.1109/vizsec.2005.1532071</mixed-citation></ref><ref id="scirp.68736-ref9"><label>9</label><mixed-citation publication-type="book" xlink:type="simple">Mehta, V., Bartzis, C., Zhu, H., Clarke, E.M. and Wing, J.M. (2006) Ranking Attack Graphs. In: Zamboni, D. and Krügel, C., Eds., Recent Advances in Intrusion Detection, Volume 4219, Lecture Notes in Computer Science, Springer, Berlin, 127-144. http://dx.doi.org/10.1007/11856214_7</mixed-citation></ref><ref id="scirp.68736-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H. and Malaiya, Y.K. (2008) Application of Vulnerability Discovery Models to Major Operating Systems. IEEE Transactions on Reliability, 57, 14-22. http://dx.doi.org/10.1109/TR.2008.916872</mixed-citation></ref><ref id="scirp.68736-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Lawler, G.F. (2006) Introduction to Stochastic processes. 2nd Edition, Chapman and Hall/CRC Taylor and Francis Group, London, New York.</mixed-citation></ref><ref id="scirp.68736-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Jajodia, S. and Noel, S. (2005) Advanced Cyber Attack Modeling, Analysis, and Visualization. 14th USENIX Security Symposium, Technical Report 2010, George Mason University, Fairfax.</mixed-citation></ref><ref id="scirp.68736-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Abraham, S. and Nair, S. (2014) Cyber Security Analytics: A Stochastic Model for Security Quantification Using Absorbing Markov Chains. Journal of Communications, 9, 899-907. http://dx.doi.org/10.12720/jcm.9.12.899-907</mixed-citation></ref><ref id="scirp.68736-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Wang, L., Singhal, A. and Jajodia, S. (2007) Measuring Overall Security of Network Configurations Using Attack Graphs. Data and Applications Security XXI, 4602, 98-112. http://dx.doi.org/10.1007/978-3-540-73538-0_9</mixed-citation></ref><ref id="scirp.68736-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Wang, L., Islam, T., Long, T., Singhal, A. and Jajodia, S. (2008) An Attack Graph-Based Probabilistic Security Metric. DAS 2008, LNCS 5094, 283-296.</mixed-citation></ref><ref id="scirp.68736-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H. and Malaiya, Y.K. (2005) Modeling the Vulnerability Discovery Process. Proceedings of 16th International Symposium on Software Reliability Engineering, Chicago, 8-11 November 2005, 129-138.  
http://dx.doi.org/10.1109/ISSRE.2005.30</mixed-citation></ref></ref-list></back></article>