arXiv:2506.06604cs.CRcs.LG2025-06被引 1

用网站技术签名评估企业网络安全风险,更准更普适。

Scoring the Unscorables: Cyber Risk Assessment Beyond Internet Scans

  • 通过爬取企业网站获取技术签名数据,替代传统扫描漏洞
  • 模型对数据泄露概率预测准确,尤其适用于中小企业
  • 揭示勒索软件受害者与普通受害者的风险差异

本文研究如何利用新型数据类型进行网络风险量化,评估数据泄露可能性。我们证明,仅通过爬取企业网站即可获取公开且易得的技术数字签名,构建高精度的网络安全风险评估模型。该方法克服了以往依赖大规模IP扫描数据的局限性,后者存在IP映射不全、中小型企业(SMEs)数据缺失等问题。相比扫描数据,技术签名数据可覆盖数百万中小企业。研究显示,这些技术签名与组织网络安全态势存在强关联。在不同网络事件数据集上的交叉验证中,我们还揭示了勒索软件攻击受害者与更广泛网络事件及数据泄露受害者的关键差异。

原文摘要 · Abstract (English)

In this paper we present a study on using novel data types to perform cyber risk quantification by estimating the likelihood of a data breach. We demonstrate that it is feasible to build a highly accurate cyber risk assessment model using public and readily available technology signatures obtained from crawling an organization's website. This approach overcomes the limitations of previous similar approaches that relied on large-scale IP address based scanning data, which suffers from incomplete/missing IP address mappings as well as the lack of such data for large numbers of small and medium-sized organizations (SMEs). In comparison to scan data, technology digital signature data is more readily available for millions of SMEs. Our study shows that there is a strong relationship between these technology signatures and an organization's cybersecurity posture. In cross-validating our model using different cyber incident datasets, we also highlight the key differences between ransomware attack victims and the larger population of cyber incident and data breach victims.

网络安全风险评估数据挖掘中小企业

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。