J. Goel, Mohsen Hallaj Asghar, Vivek Kumar, S. Pandey
{"title":"Ensemble based approach to increase vulnerability assessment and penetration testing accuracy","authors":"J. Goel, Mohsen Hallaj Asghar, Vivek Kumar, S. Pandey","doi":"10.1109/ICICCS.2016.7542303","DOIUrl":null,"url":null,"abstract":"Vulnerability Assessment and Penetration Testing is an important activity to improve cyber defense of systems/networks. It assist to make systems/networks vulnerability free. But it is a costly process. Premium VAPT tools are very costly. Even premium VAPT tools are not able to give 100 % accuracy to find out vulnerability. In addition to that, single VAPT tool cannot find all type of vulnerabilities. So there is a need of a model that can find out all type vulnerabilities, gives almost 100 % accuracy and do not cost more. To achieve this goal we made an Ensemble approach of VAPT tools. Our approach combine multiple VAPT tools (open source/premium) and apply majority voting and weighted priority. Our approach provide better accuracy and more versatility. Our approach provide cost effective solution for vulnerability analysis and penetration testing. After that we made a software to implement this approach called `VEnsemble 1.0'. We have also presented implemented software and results in this paper.","PeriodicalId":389065,"journal":{"name":"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)","volume":"22 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-02-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Conference on Innovation and Challenges in Cyber Security (ICICCS-INBUSH)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICICCS.2016.7542303","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14
Abstract
Vulnerability Assessment and Penetration Testing is an important activity to improve cyber defense of systems/networks. It assist to make systems/networks vulnerability free. But it is a costly process. Premium VAPT tools are very costly. Even premium VAPT tools are not able to give 100 % accuracy to find out vulnerability. In addition to that, single VAPT tool cannot find all type of vulnerabilities. So there is a need of a model that can find out all type vulnerabilities, gives almost 100 % accuracy and do not cost more. To achieve this goal we made an Ensemble approach of VAPT tools. Our approach combine multiple VAPT tools (open source/premium) and apply majority voting and weighted priority. Our approach provide better accuracy and more versatility. Our approach provide cost effective solution for vulnerability analysis and penetration testing. After that we made a software to implement this approach called `VEnsemble 1.0'. We have also presented implemented software and results in this paper.