Attacker economics for Internet-scale vulnerability risk assessment

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

36 Downloads (Pure)


Vulnerability risk assessment is a crucial process in security management, and the CVSS score is the standard-de-facto risk metric for software vulnerabilities. In this manuscript I show that current risk assessment methodologies do not fit real “in the wild” attack data. I also present my three-steps plan to identify an Internet-scale risk assessment methodology that accounts for attacker economics and opportunities. Eventu- ally, I want to provide answers like the following: “If we de- ploy this security measure, the fraction of our users affected by this type of cyber attacks will be less than X%”.
Original languageEnglish
Title of host publicationUSENIX LEET
PublisherUsenix Association
Number of pages4
Publication statusPublished - 2013
Externally publishedYes


Dive into the research topics of 'Attacker economics for Internet-scale vulnerability risk assessment'. Together they form a unique fingerprint.

Cite this