<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">JIS</journal-id><journal-title-group><journal-title>Journal of Information Security</journal-title></journal-title-group><issn pub-type="epub">2153-1234</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/jis.2018.91002</article-id><article-id pub-id-type="publisher-id">JIS-80734</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject></subj-group></article-categories><title-group><article-title>
 
 
  Non-Homogeneous Stochastic Model for Cyber Security Predictions
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Pubudu</surname><given-names>Kalpani Kaluarachchi</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Chris</surname><given-names>P. Tsokos</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Sasith</surname><given-names>M. Rajasooriya</given-names></name><xref ref-type="aff" rid="aff3"><sup>3</sup></xref></contrib></contrib-group><aff id="aff3"><addr-line>Department of Statistics, Miami University, Oxford, Ohio, USA</addr-line></aff><aff id="aff2"><addr-line>Distinguished University Professor, Department of Mathematics and Statistics, University of South Florida, Tampa, Florida, USA</addr-line></aff><aff id="aff1"><addr-line>Department of Mathematical and Physical Sciences, Miami University, Middletown, Ohio, USA</addr-line></aff><pub-date pub-type="epub"><day>22</day><month>11</month><year>2017</year></pub-date><volume>09</volume><issue>01</issue><fpage>12</fpage><lpage>24</lpage><history><date date-type="received"><day>29,</day>	<month>October</month>	<year>2017</year></date><date date-type="rev-recd"><day>27,</day>	<month>November</month>	<year>2017</year>	</date><date date-type="accepted"><day>30,</day>	<month>November</month>	<year>2017</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution-NonCommercial International License (CC BY-NC).http://creativecommons.org/licenses/by-nc/4.0/</license-p></license></permissions><abstract><p>
 
 
  
    Any computer system with known vulnerabilities can be presented using attack graphs. An attacker generally has a mission to reach a goal state that he expects to achieve. 
   Expected Path Length (EPL) 
   [1] in the context of an attack graph describes the length or number of steps that the attacker has to take in achieving the goal state. However, 
   EPL varies and it is based on the “
   state of vulnerabilities” 
   [2] 
   [3] in a given computer system. Any vulnerability throughout its life cycle passes through several stages that we identify as “
   states of the vulnerability life cycle” 
   [2] 
   [3]. In our previous studies we have developed mathematical models using Markovian theory to estimate the probability of a given vulnerability being in a particular state of its life cycle. There, we have considered a typical model of a computer network system with two computers subject to three vulnerabilities, and developed a method driven by an algorithm to estimate the EPL of this network system as a function of time. This approach is important because it allows us to monitor a computer system during the process of being exploited. Proposed 
   non-homogeneous model in this study estimates the behavior of the
    EPL as a function of time and therefore act as an index of the risk associated with the network system getting exploited. 
  
 
</p></abstract><kwd-group><kwd>Vulnerability</kwd><kwd> Attack Graph</kwd><kwd> Markov Model</kwd><kwd> Security Evaluation</kwd><kwd> Expected Path Length (EPL)</kwd><kwd> Common Vulnerability Scoring System (CVSS)</kwd><kwd> Non Homogeneous Stochastic Model</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>In 2016, the U.S. Government Cybersecurity report commences with the following paragraph. [<xref ref-type="bibr" rid="scirp.80734-ref4">4</xref>] “In July 2015, hackers stole social security numbers, health data, and other highly sensitive data from 21 million Americans through the Office of Personnel Management in what, at the time, was the largest data breach in U.S. history. As a response, U.S. government agencies committed to making significant efforts to reinforce and expand existing security measures. Security Scorecard wanted to find out if these government agencies were successful in their commitment”. “Symantec corporation”, in their “Internet security threat report 2016-Volume 21” [<xref ref-type="bibr" rid="scirp.80734-ref5">5</xref>] presents with records on rapidly increasing vulnerabilities, security threats, susceptibility of systems that motivates researchers to study these important issues on Cybersecurity measures. Cybersecurity is one of the critical issues that our global society is facing on daily basis. It is now a part of our daily life and culture and has become an index of personal security and integrity.</p><p>To address this scenario, many research efforts have been taken. However, due to the peculiar, voluminous and dynamic nature of the field, defending methods are still chasing behind the defending targets. Therefore, it is extremely important to integrate scientific efforts and develop strong theoretical basis aiming for rapid development of applications and system solutions.</p><p>In this study, we continue our research efforts in integrating Mathematical and Statistical theories into better understanding the complex behavior of computer network systems in the perspective of Cybersecurity. Thus, we propose a new method to estimate the EPL as a function of time “t”. The EPL is a major factor in determining the risk level of a given computer system where with smaller EPL, the network system is more vulnerable and probable to be exploited.</p><p>In our recent studies, [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] , we introduced several stochastic models to better understand the behavior of vulnerabilities, network systems with respect to cybersecurity. Initially, we introduced a stochastic model that can estimate the Expected Path Length of a system with any three vulnerabilities and two machines. Then, we introduced a new approach of estimating the probability of a given vulnerability being exploited at a time t, using Markovian approach with respect to the Vulnerability life cycle. We have further introduced a set of three stochastic time dependent models for each categories of vulnerabilities with Low, Medium and High exploitability scores [<xref ref-type="bibr" rid="scirp.80734-ref6">6</xref>] that can estimate the probability of a given vulnerability getting exploited without going through the Markovian process [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref7">7</xref>] each time. Additionally, the concept of “Risk Factor” [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] that we introduced and its analytical formulation allowed us to present a more sophisticated way of estimating the risk associated with a specific vulnerability of a computer network system.</p><p>In the present study, we introduce a Non Homogeneous Stochastic Model that allows the computer system administrators to predict the time that the system is most vulnerable for an attack in terms of the EPL. This estimate is based on the assumption that a system is more susceptible to be exploited when the EPL is at a minimum at a particular time “t”. In developing this model we have used a network system of two IPs with three vulnerabilities as a base model.</p><p>With the introduction of this new approach we will be re-defending the capability to estimate the probability of getting exploited as a function of time for a computer network system with given set of vulnerabilities. Even though we have already developed a successful statistical model to find the EPL of a possible attack, it is more important to estimate the EPL as a function of time. Current study will address this need. Thus, for a system with a given set of vulnerabilities, estimating of most probable exploit times can be modelled on the logical assumption that a system is more susceptible to be exploited at a time where the Expected Path Length (number of steps that an attacker needs to pass before achieving the goal state) is at its minimum.</p></sec><sec id="s2"><title>2. Methodology</title><sec id="s2_1"><title>2.1. Cybersecurity Analysis Method</title><p>The core component of this method is the attack graph [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref7">7</xref>] . An attack graph for a cybersecurity system has several nodes, which represent both the vulnerabilities that exist in the system and the attacker’s states [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref7">7</xref>] . We consider that it is possible to go to a goal state starting from any other state in the attack graph. This possibility depends on several factors such as the attacker’s attacking strategy, recourses, system design, networking, authenticating protocols, human interface and other environmental factors. An attack graph has at least one “Absorbing state” named “Goal state”, which is, the state where the attacker will reach his objective and cannot go beyond. Therefore we will model the attack graph as an absorbing Markov chain [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] .</p><p>Absorbing state or goal state is the security node which the attacker expects to reach and exploit. When the attacker has reached this goal state, the attack path is completed. Thus, the entire attack graph consists of these types of attack paths that will be illustrated in this study.</p><p>Given the CVSS score [<xref ref-type="bibr" rid="scirp.80734-ref8">8</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref9">9</xref>] for each vulnerability in the attack Graph, we can estimate the transition probabilities of the absorbing Markov chain by normalizing the CVSS scores over all the edges starting from the attacker’s source state (initial state). The analytical methodology that we used is explained below.</p><p>We define,</p><p>j = probability that an attacker is currently in state i and exploits a vulnerability in state.</p><p>n = number of outgoing edges from state i in the attack model.</p><p>v<sub>j</sub> = CVSS score of the vulnerability in state j.</p><p>Thus formally we can define the transition probability given by,</p><p>p i j = v j ∑ k = 1 n     v k</p><p>Now, using these transition probabilities we can derive the absorbing transition probability matrix P, which possesses the properties defined under Markov chain probability methods.</p></sec><sec id="s2_2"><title>2.2. Risk Factor Model</title><p>p i j , the transition probabilities for each state in an attack graph represent the risk of a particular state (for a given vulnerability) of being exploited. Therefore, it is logical to consider it as a risk variable. In our previous studies we have introduced a more convenient tool named “Risk Factor” [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] that can estimate the risk associated with a particular state of a given vulnerability.</p><p>It is important to note that when we consider a given vulnerability, its exploitability factor should vary with time. But the exploitability factor calculated under the CVSS is a constant and is not suitable for inclusion in a non-homogenous model. However, our “Risk Factor” model is based on the Vulnerability Life Cycle [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref10">10</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref11">11</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref12">12</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref13">13</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref14">14</xref>] and it is time dependent. This allows us to develop a non-homogeneous model which is our objective in this study. Therefore, in this study we will extend the Transition Probability Matrix Model, replacing vulnerability with the CVSS, “v” by its Risk Factor “r”.</p><p>The probability of an exploitation for a given vulnerability can be obtained using the three stochastic models given in <xref ref-type="table" rid="table1">Table 1</xref> below. These time dependent stochastic models were developed in our previous study [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] , and we used the general classification of vulnerability risks based on the CVSS identified as Low, Medium and High. Details of the process and methodology in developing the subject models along with their validation accuracy were given in our previous study [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] .</p><p>In each of the equations, t is the age of vulnerability and is calculated by taking the difference between the dates that the vulnerability was first discovered and the attacking attempt started.</p><p>Thus, for a given vulnerability at a time we can obtain the probability of being exploited. We can now define the transition probability as follows.</p><p>p i j = R ( v j ( t ) ) ∑ j = 1 n     R ( v j (t))</p><p>(v<sub>j</sub>(t)) = Risk Factor of a given vulnerability in state j at time t,</p><p>e(v<sub>j</sub>) = Exploitability sub score that is related to the CVSS score for the given vulnerability in state j.</p><p>And</p><p>R ( v j ( t ) ) = Y ( t ) ∗ e (vj)</p><table-wrap id="table1" ><label><xref ref-type="table" rid="table1">Table 1</xref></label><caption><title> Model equations of risk factors for three different categories of vulnerabilities</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Category</th><th align="center" valign="middle" >Model Equation</th><th align="center" valign="middle" >R<sup>2</sup></th><th align="center" valign="middle" >R a d j 2</th></tr></thead><tr><td align="center" valign="middle" >Low (0 - 4)</td><td align="center" valign="middle" >Y(t) = 0.135441 − 0.308532 (1/t) − 0.002030ln(lnt)</td><td align="center" valign="middle" >0.9576</td><td align="center" valign="middle" >0.9566</td></tr><tr><td align="center" valign="middle" >Medium (4 - 7)</td><td align="center" valign="middle" >Y(t) = 0.169518 − 0.356821(1/t) − 0.007011ln(lnt)</td><td align="center" valign="middle" >0.962</td><td align="center" valign="middle" >0.961</td></tr><tr><td align="center" valign="middle" >High (7 - 10)</td><td align="center" valign="middle" >Y(t) = 0.191701 − 0.383521 (1/t) − 0.00358ln(lnt)</td><td align="center" valign="middle" >0.9588</td><td align="center" valign="middle" >0.9577</td></tr></tbody></table></table-wrap><p>is the analytic form of the risk factor as a function of Y(t) and e(v<sub>j</sub>) where Y(t) is the exploitability probability factor as a function of time and e(v<sub>j</sub>) is the exploitability score taken from the CVSS.</p></sec><sec id="s2_3"><title>2.3. Attack Prediction</title><p>Under the Attack Prediction, we consider two methods to predict the attacker’s behavior.</p><sec id="s2_3_1"><title>2.3.1. Multi Step Attack Prediction</title><p>The absorbing transition probability matrix [<xref ref-type="bibr" rid="scirp.80734-ref15">15</xref>] shows the presence of each edge in a network attack graph. This matrix shows every possible single-step attack. In other words, the absorbing transition probability matrix shows attackers reachability within one attack step. We can navigate the absorbing transition probability matrix by iteratively matching rows and columns to follow multiple attack steps, and also raise the absorbing transition probability matrix to higher powers, which shows multi-step attacker reachability at a glance.</p><p>For a square (n &#215; n) adjacency matrix P and a positive integer k, P<sup>k</sup> is matrix P raised to the power of k. Since P is an absorbing transition probability matrix with respect to time, this matrix goes to some stationary matrix Π, where the rows of this matrix are identical as follows. That is,</p><p>lim k → ∞ P k = Π</p><p>Once the stationarity is achieved, goal state column of this matrix Π has ones, so we can find the minimum number of steps (time) that the attacker will reach the goal state with probability 1. Once the attacker is in the goal state we can identify the probability of the system being exploited.</p></sec><sec id="s2_3_2"><title>2.3.2. Prediction of Expected Path Length (EPL)</title><p>The Expected Path Length (EPL) measures the expected number of steps the attacker will need starting from the initial state to reach the goal state (the attacker’s objective). As we discussed earlier P has the following canonical form,</p><p>P = ( Q R 0 I )</p><p>Here, P is the transition matrix, Q is the matrix of transient states, R is the matrix of absorbing states and I is the identity matrix.</p><p>The matrix P represents the transition probability matrix of the absorbing Markov chain. In an absorbing Markov chain the probability that the chain will be absorbed is always 1. Thus, we have</p><p>Q n → 0     as   n → ∞</p><p>This property implies that all the eigenvalues of Q have absolute values strictly less than 1. Thus, I − Q is an invertible matrix and there is no problem in defining the matrix</p><p>M = ( I − Q ) − 1 = I + Q + Q 2 + Q 3 + ⋯</p><p>Using this fundamental matrix M of the absorbing Markov chain we can compute the expected total number of steps to reach the goal state until absorption.</p><p>Taking the summation of the first row elements of matrix M gives us the expected total number of steps to reach the goal state which is defined as the Expected Path Length.</p><p>Given below is an application that illustrates a computer network system of our proposed analytic process to estimate the EPL of a hacker.</p></sec></sec></sec><sec id="s3"><title>3. Attack Graph and Attack Risk Evaluation</title><p>In this section we present an example illustrating the application of the usefulness of our method. We combine the application of methodology with an attack graph relevant to a typical network exemplified with three different recorded vulnerabilities.</p><sec id="s3_1"><title>3.1. Application: The Attacker</title><p>To illustrate the proposed analytical approach model that we have developed as discussed above, we considered the Network Topology [<xref ref-type="bibr" rid="scirp.80734-ref1">1</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref16">16</xref>] - [<xref ref-type="bibr" rid="scirp.80734-ref21">21</xref>] , given by <xref ref-type="fig" rid="fig1">Figure 1</xref> below.</p><p>The computer network consists of two service hosts IP 1, IP 2 and an attacker’s workstation, Attacker connecting to each of the servers via a central router.</p><p>In the server IP 1 the vulnerability is labeled as CVE 2016-3230 and shall be denoted as V<sub>1</sub>.</p><p>In the server IP 2 there are two recognized vulnerabilities, which are labeled CVE 2016-2832 and CVE 2016-0911. Let’s denote them as V<sub>2</sub> and V<sub>3</sub>, respectively.</p><p>We proceed to use the CVSS score of the above vulnerabilities in our analysis. The exploitability score (e (v) in <xref ref-type="fig" rid="fig1">Figure 1</xref>) of each vulnerability is given in <xref ref-type="table" rid="table2">Table 2</xref> below.</p><p>Published date is in general considered as the date that a vulnerability is made known to the public. CVSS score is the score given to the vulnerability based on exploitability factors by the “Forum of Incident Response and Security Teams”, (FIRST). Calculation of this score is established and updated time to time</p><table-wrap id="table2" ><label><xref ref-type="table" rid="table2">Table 2</xref></label><caption><title> Vulnerability scores</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Vulnerability</th><th align="center" valign="middle" >Published date</th><th align="center" valign="middle" >CVSS score</th><th align="center" valign="middle" >Exploitability score</th><th align="center" valign="middle" >Time for the date 6/24/2016 (t<sub>j</sub>)</th><th align="center" valign="middle" >Risk factor R(ν<sub>j</sub>(t<sub>j</sub>))</th></tr></thead><tr><td align="center" valign="middle" >V<sub>1</sub> (CVE 2016-3230)</td><td align="center" valign="middle" >6/15/2016</td><td align="center" valign="middle" >9 (High)</td><td align="center" valign="middle" >8</td><td align="center" valign="middle" >9</td><td align="center" valign="middle" >1.702</td></tr><tr><td align="center" valign="middle" >V<sub>2</sub> (CVE 2016-2832)</td><td align="center" valign="middle" >6/13/2016</td><td align="center" valign="middle" >4.3 (medium)</td><td align="center" valign="middle" >2.8</td><td align="center" valign="middle" >11</td><td align="center" valign="middle" >0.3667</td></tr><tr><td align="center" valign="middle" >V<sub>3</sub> (CVE 2016-0911)</td><td align="center" valign="middle" >6/19/2016</td><td align="center" valign="middle" >1.9 (Low)</td><td align="center" valign="middle" >3.4</td><td align="center" valign="middle" >5</td><td align="center" valign="middle" >0.2474</td></tr></tbody></table></table-wrap><p>and the relevant details are available in the CVE detail and other relevant official websites.</p><p>June 24th was used as the date where a first attack attempt was made by an attacker. Risk factor is hence the Risk of being exploited on the 24th of June, calculated using the equation presented in the Section 2.2. That is,</p><p>( v j ( t ) ) = Y ( t ) ∗ e (vj)</p><p>For example, let’s consider the vulnerability “V1 (CVE 2016-3230)”. The CVSS score has given the exploitability score for this vulnerability as 8. Taking the difference between the published date (June 15th) and the attack date (June 24th), the age of this vulnerability is calculated as 9 days. Since this is a vulnerability of the category “High”, we can now use our model given in the <xref ref-type="table" rid="table1">Table 1</xref> and calculate the “Risk Factor” as follows.</p><p>R ( v 1 ( t ) ) = [ 0.191701 − 0.383521 ( 1 t ) − 0.00358 ln ( ln t ) ] ∗ 8</p><p>R ( v 1 ( 9 ) ) = 1.702</p><p>Similarly, Risk factors for two other vulnerabilities are also calculated and presented in the <xref ref-type="table" rid="table2">Table 2</xref> below.</p></sec><sec id="s3_2"><title>3.2. Host Centric Attack Graph</title><p>The host centric attack graph is shown by <xref ref-type="fig" rid="fig2">Figure 2</xref>, below. Here, we consider that the attacker can reach the goal state only by exploiting V<sub>3</sub> vulnerability. The graph shows all the possible paths that the attacker can follow to reach the goal state.</p><p>Note that IP1.1 state represents V<sub>1</sub> vulnerability and IP2.1 and IP2.2 states represent vulnerabilities V<sub>2</sub> and V<sub>3</sub> respectively. Attacker can reach each state by exploiting the relevant Vulnerability.</p></sec><sec id="s3_3"><title>3.3. Adjacency Matrix for the Attack Graph</title><p>In this section we will illustrate the process of developing Adjacency Matrix for the Attack Graph. Adjacency Matrix is a key analytical tool used in out methodology.</p><p>Let s<sub>1</sub>, s<sub>2</sub>, s<sub>3</sub>, s<sub>4</sub>, represent the attack states for Attacker, (IP1.1), (IP2.1) and (IP2.2), respectively.</p><p>To find the weighted value of exploiting each vulnerability from one state to another state, we divide the vulnerability score by summation of all out going vulnerability values from that state.</p><p>For our attack graph the weighted value of exploiting each vulnerability is given below. 1st row probabilities:</p><p>Weighted value of exploiting V<sub>1</sub> from s<sub>1</sub> to s<sub>2</sub> is R<sub>1</sub>/(R<sub>1</sub> + R<sub>2</sub>) Weighted value of exploiting V<sub>2</sub> from s<sub>1</sub> to s<sub>3</sub> is R<sub>2</sub>/(R<sub>1</sub> + R<sub>2</sub>) 2nd row probabilities:</p><p>Weighted value of exploiting V<sub>2</sub> from s<sub>2</sub> to s<sub>3</sub> is R<sub>2</sub>/(R<sub>2</sub>) 3rd row probabilities:</p><p>Weighted value of exploiting V<sub>1</sub> from s<sub>3</sub> to s<sub>2</sub> is R<sub>1</sub>/(R<sub>1</sub> + R<sub>3</sub>) Weighted value of exploiting V<sub>3</sub> from s<sub>3</sub> to s<sub>4</sub> is R<sub>3</sub>/(R<sub>1</sub> + R<sub>3</sub>) 4th row probabilities:</p><p>Weighted value of exploiting V<sub>3</sub> from s<sub>4</sub> to s<sub>4</sub> is 1.</p><p>For the Host Centric Attack graph we can have the Adjacency Matrix as follows.</p><p>Applying the information given in <xref ref-type="table" rid="table1">Table 1</xref>, the matrix A can be obtained as follows.</p><p>                      s 1             s 2                       s 3                     s 4 A = s 1 s 2 s 3 s 4 [ 0 0.7614 0.2386 0 0 0 1 0 0 0.8255 0 0.1745 0 0 0 1 ]</p><p>Here, 0.7614 is the probability that attacker exploits vulnerability V<sub>1</sub> in the first step, the step from s<sub>1</sub> to s<sub>2</sub>. Similarly, we can explain 0.1745 as the probability that attacker exploits the vulnerability V<sub>3</sub> in the step s<sub>2</sub> to s<sub>3</sub> in his first attempt. Similarly, each probability represents the likelihood to exploit relevant vulnerability from one state to another state in the first attempt.</p><p>We can use this matrix to answer several important questions in cyber security analysis. First, using the Adjacency Matrix we expect to find the Expected Path Length. Then, we can analyze the behavior of Expected Path Length over the time.</p><p>To calculate the EPL over the time we follow the steps given below.</p><p>Step 1: Calculate the “Risk Factor” of each vulnerability on the date of the first attack assumed (June 24th in our application). That is, calculate the “age” of each vulnerability by taking the difference between the published date and the 24th of June. And, substitute this value of “t” in relevant model equation given in the <xref ref-type="table" rid="table1">Table 1</xref>.</p><p>Step 2: Using those “Risk Factors”, develop the transition matrix “A” and calculate the EPL.</p><p>Step 3: Repeat the same process for all the following dates that we need to calculate the</p><p>Expected Path Length.</p><p>From <xref ref-type="table" rid="table3">Table 3</xref> below, we can identify that the number of days a hacker will take to reach his goal of exploitability for the given computer network system we have structured.</p><p>For example, let’s consider the 20th day. Under step 1, we calculate the Risk factors for V<sub>1</sub>, V<sub>2</sub> and V<sub>3</sub>. For the 20th day age of three vulnerabilities V<sub>1</sub>, V<sub>2</sub> and V<sub>3</sub> are, t<sub>1</sub> = 9 + 20, t<sub>2</sub> = 11 + 20 and t<sub>3</sub> = 5 + 20, respectively. Then, by substituting these ages in the respective model equation from the <xref ref-type="table" rid="table1">Table 1</xref> and multiplying the answers by respective exploitability score, we calculate three risk factors as follows.</p><p>V<sub>1</sub> is a vulnerability of “High” category. Therefore, we use the 3rd model equation from <xref ref-type="table" rid="table1">Table 1</xref> and obtain the Risk factor as follows.</p><p>Substituting, t = 29, in the model,</p><p>( v 1 ( t ) ) = Y ( t ) ∗ e (v1)</p><p>we obtain,</p><p>R 1 = 0.191701 − 0.383521 &#215; ( 1 / 29 ) − 0.00358 ln ( ln 29 ) &#215; 8 = 1.393</p><p>Similarly for V<sub>2</sub> and V<sub>3</sub> we obtain the following Risk factors calculated using the relevant model equations.</p><p>For, t = 31,</p><p>( v 2 ( t ) ) = Y ( t ) ∗ e (v2)</p><p>R 2 = 0.169518 − 0.356821 &#215; ( 1 / 31 ) − 0.007011 ln ( ln 31 ) &#215; 2.8 = 0.4182</p><p>For, t = 25,</p><p>( v 3 ( t ) ) = Y ( t ) ∗ e (v3)</p><p>R 3 = 0.135441 − 0.308532 &#215; ( 1 / 25 ) − 0.002030 ln ( ln 25 ) &#215; 3.4 = 0.4105</p><p>Once we have calculated the “Risk Factors” for all the vulnerabilities in the network system, the second step is to develop the Transition Matrix “A” as given in the <xref ref-type="fig" rid="fig3">Figure 3</xref>.</p><p>The transition probability Matrix for this system on the 20th day after the first attack attempt is assumed to be made is given below.</p><p>                      s 1             s 2                       s 3                     s 4 A = s 1 s 2 s 3 s 4 [ 0 0.7691 0.2309 0 0 0 1 0 0 0.7724 0 0.2276 0 0 0 1 ]</p><p>Step 3 is to calculate the EPL. Applying the methodology we explained in the Section 2.3.2. we can calculate the EPL using the transition matrix “A” by obtaining the matrix “M”.</p><p>The sum of the first row of matrix “M” is the EPL of this computer network system at the 20th day (from June 24th) from the first assumed attack attempt. We have obtained, EPL = 9.567 for the 20th day after the first attack created as given in the <xref ref-type="table" rid="table3">Table 3</xref>.</p><p>Expected Path length</p><p>The <xref ref-type="table" rid="table3">Table 3</xref> below shows us the EPL for this computer system for 100 days starting from 24th of June.</p><p><xref ref-type="fig" rid="fig4">Figure 4</xref> below illustrates the results shown in the <xref ref-type="table" rid="table3">Table 3</xref>, graphically.</p><p>By examining the distribution of Expected Path Length of the attacker over 100 days, it will take fewer steps for an attacker to compromise the security goal as the age of vulnerabilities increases. Security practitioners in a typical organization can establish a threshold score for the system and the security teams can planned in advance and identify the critical points to establish a strategy to defend the security of the computer system and introduce relevant patches before we approach such critical stages.</p><p>In the present system, it is clear that the threshold score of the EPL is approximately 9.5 steps and the defending professionals can conclude that the system in their network is relatively safe from exploits only for the next 21 days as EPL score is above the threshold value.</p><p>It is also clear that any vulnerability that exists creates a threat to the computer system and the risk of probable exploitation will increase over the time of its existence without being patched. In other words, for a particular network system, a higher Expected Path Length for an attacker to reach a goal state represents more difficulty for the hacker and would be reasonable to assume that the attacker has to face many defending measures with a higher Expected Path Length compared to a smaller Expected Path Length. Now, using the probabilistic models that we have developed in our previous studies, using the Vulnerability Life Cycle approach [<xref ref-type="bibr" rid="scirp.80734-ref2">2</xref>] [<xref ref-type="bibr" rid="scirp.80734-ref3">3</xref>] enables us to develop a time dependent stochastic models so that we could extend their application to develop a relevant and well defined process of monitoring the behavior of threats. Thus, our proposed analytic process illustrates its capability of estimating a Risk Index as a function of the attacking time for a given computer system with known vulnerabilities.</p><table-wrap id="table3" ><label><xref ref-type="table" rid="table3">Table 3</xref></label><caption><title> Expected path length relative to number of days after first attack</title></caption><table><tbody><thead><tr><th align="center" valign="middle" >Age (Days)</th><th align="center" valign="middle" >Expected Path Length</th><th align="center" valign="middle" >Age (Days)</th><th align="center" valign="middle" >Expected Path Length</th><th align="center" valign="middle" >Age (Days)</th><th align="center" valign="middle" >Expected Path Length</th><th align="center" valign="middle" >Age (Days)</th><th align="center" valign="middle" >Expected Path Length</th></tr></thead><tr><td align="center" valign="middle" >1</td><td align="center" valign="middle" >12.2205398</td><td align="center" valign="middle" >26</td><td align="center" valign="middle" >9.517537</td><td align="center" valign="middle" >51</td><td align="center" valign="middle" >9.4453151</td><td align="center" valign="middle" >76</td><td align="center" valign="middle" >9.4239414</td></tr><tr><td align="center" valign="middle" >2</td><td align="center" valign="middle" >11.3052188</td><td align="center" valign="middle" >27</td><td align="center" valign="middle" >9.511655</td><td align="center" valign="middle" >52</td><td align="center" valign="middle" >9.4440137</td><td align="center" valign="middle" >77</td><td align="center" valign="middle" >9.4234008</td></tr><tr><td align="center" valign="middle" >3</td><td align="center" valign="middle" >10.7998722</td><td align="center" valign="middle" >28</td><td align="center" valign="middle" >9.506248</td><td align="center" valign="middle" >53</td><td align="center" valign="middle" >9.4427673</td><td align="center" valign="middle" >78</td><td align="center" valign="middle" >9.4228753</td></tr><tr><td align="center" valign="middle" >4</td><td align="center" valign="middle" >10.4850373</td><td align="center" valign="middle" >29</td><td align="center" valign="middle" >9.501261</td><td align="center" valign="middle" >54</td><td align="center" valign="middle" >9.4415727</td><td align="center" valign="middle" >79</td><td align="center" valign="middle" >9.4223643</td></tr><tr><td align="center" valign="middle" >5</td><td align="center" valign="middle" >10.2729754</td><td align="center" valign="middle" >30</td><td align="center" valign="middle" >9.49665</td><td align="center" valign="middle" >55</td><td align="center" valign="middle" >9.4404267</td><td align="center" valign="middle" >80</td><td align="center" valign="middle" >9.4218672</td></tr><tr><td align="center" valign="middle" >6</td><td align="center" valign="middle" >10.1220591</td><td align="center" valign="middle" >31</td><td align="center" valign="middle" >9.492376</td><td align="center" valign="middle" >56</td><td align="center" valign="middle" >9.4393265</td><td align="center" valign="middle" >81</td><td align="center" valign="middle" >9.4213834</td></tr><tr><td align="center" valign="middle" >7</td><td align="center" valign="middle" >10.0101501</td><td align="center" valign="middle" >32</td><td align="center" valign="middle" >9.488404</td><td align="center" valign="middle" >57</td><td align="center" valign="middle" >9.4382695</td><td align="center" valign="middle" >82</td><td align="center" valign="middle" >9.4209123</td></tr><tr><td align="center" valign="middle" >8</td><td align="center" valign="middle" >9.9244658</td><td align="center" valign="middle" >33</td><td align="center" valign="middle" >9.484705</td><td align="center" valign="middle" >58</td><td align="center" valign="middle" >9.4372532</td><td align="center" valign="middle" >83</td><td align="center" valign="middle" >9.4204536</td></tr><tr><td align="center" valign="middle" >9</td><td align="center" valign="middle" >9.8571518</td><td align="center" valign="middle" >34</td><td align="center" valign="middle" >9.481253</td><td align="center" valign="middle" >59</td><td align="center" valign="middle" >9.4362752</td><td align="center" valign="middle" >84</td><td align="center" valign="middle" >9.4200067</td></tr><tr><td align="center" valign="middle" >10</td><td align="center" valign="middle" >9.8031388</td><td align="center" valign="middle" >35</td><td align="center" valign="middle" >9.478024</td><td align="center" valign="middle" >60</td><td align="center" valign="middle" >9.4353336</td><td align="center" valign="middle" >85</td><td align="center" valign="middle" >9.4195711</td></tr><tr><td align="center" valign="middle" >11</td><td align="center" valign="middle" >9.7590231</td><td align="center" valign="middle" >36</td><td align="center" valign="middle" >9.474999</td><td align="center" valign="middle" >61</td><td align="center" valign="middle" >9.4344263</td><td align="center" valign="middle" >86</td><td align="center" valign="middle" >9.4191465</td></tr><tr><td align="center" valign="middle" >12</td><td align="center" valign="middle" >9.7224429</td><td align="center" valign="middle" >37</td><td align="center" valign="middle" >9.472158</td><td align="center" valign="middle" >62</td><td align="center" valign="middle" >9.4335516</td><td align="center" valign="middle" >87</td><td align="center" valign="middle" >9.4187324</td></tr><tr><td align="center" valign="middle" >13</td><td align="center" valign="middle" >9.6917134</td><td align="center" valign="middle" >38</td><td align="center" valign="middle" >9.469488</td><td align="center" valign="middle" >63</td><td align="center" valign="middle" >9.4327076</td><td align="center" valign="middle" >88</td><td align="center" valign="middle" >9.4183284</td></tr><tr><td align="center" valign="middle" >14</td><td align="center" valign="middle" >9.6656039</td><td align="center" valign="middle" >39</td><td align="center" valign="middle" >9.466972</td><td align="center" valign="middle" >64</td><td align="center" valign="middle" >9.4318929</td><td align="center" valign="middle" >89</td><td align="center" valign="middle" >9.4179342</td></tr><tr><td align="center" valign="middle" >15</td><td align="center" valign="middle" >9.643197</td><td align="center" valign="middle" >40</td><td align="center" valign="middle" >9.464599</td><td align="center" valign="middle" >65</td><td align="center" valign="middle" >9.431106</td><td align="center" valign="middle" >90</td><td align="center" valign="middle" >9.4175493</td></tr><tr><td align="center" valign="middle" >16</td><td align="center" valign="middle" >9.6237964</td><td align="center" valign="middle" >41</td><td align="center" valign="middle" >9.462358</td><td align="center" valign="middle" >66</td><td align="center" valign="middle" >9.4303454</td><td align="center" valign="middle" >91</td><td align="center" valign="middle" >9.4171736</td></tr><tr><td align="center" valign="middle" >17</td><td align="center" valign="middle" >9.606865</td><td align="center" valign="middle" >42</td><td align="center" valign="middle" >9.460237</td><td align="center" valign="middle" >67</td><td align="center" valign="middle" >9.4296099</td><td align="center" valign="middle" >92</td><td align="center" valign="middle" >9.4168066</td></tr><tr><td align="center" valign="middle" >18</td><td align="center" valign="middle" >9.5919829</td><td align="center" valign="middle" >43</td><td align="center" valign="middle" >9.458227</td><td align="center" valign="middle" >68</td><td align="center" valign="middle" >9.4288983</td><td align="center" valign="middle" >93</td><td align="center" valign="middle" >9.416448</td></tr><tr><td align="center" valign="middle" >19</td><td align="center" valign="middle" >9.5788176</td><td align="center" valign="middle" >44</td><td align="center" valign="middle" >9.456321</td><td align="center" valign="middle" >69</td><td align="center" valign="middle" >9.4282094</td><td align="center" valign="middle" >94</td><td align="center" valign="middle" >9.4160975</td></tr><tr><td align="center" valign="middle" >20</td><td align="center" valign="middle" >9.5671025</td><td align="center" valign="middle" >45</td><td align="center" valign="middle" >9.454511</td><td align="center" valign="middle" >70</td><td align="center" valign="middle" >9.4275421</td><td align="center" valign="middle" >95</td><td align="center" valign="middle" >9.415755</td></tr><tr><td align="center" valign="middle" >21</td><td align="center" valign="middle" >9.5566222</td><td align="center" valign="middle" >46</td><td align="center" valign="middle" >9.452789</td><td align="center" valign="middle" >71</td><td align="center" valign="middle" >9.4268956</td><td align="center" valign="middle" >96</td><td align="center" valign="middle" >9.41542</td></tr><tr><td align="center" valign="middle" >22</td><td align="center" valign="middle" >9.5472004</td><td align="center" valign="middle" >47</td><td align="center" valign="middle" >9.45115</td><td align="center" valign="middle" >72</td><td align="center" valign="middle" >9.4262687</td><td align="center" valign="middle" >97</td><td align="center" valign="middle" >9.4150924</td></tr><tr><td align="center" valign="middle" >23</td><td align="center" valign="middle" >9.5386921</td><td align="center" valign="middle" >48</td><td align="center" valign="middle" >9.449588</td><td align="center" valign="middle" >73</td><td align="center" valign="middle" >9.4256606</td><td align="center" valign="middle" >98</td><td align="center" valign="middle" >9.4147719</td></tr><tr><td align="center" valign="middle" >24</td><td align="center" valign="middle" >9.5309766</td><td align="center" valign="middle" >49</td><td align="center" valign="middle" >9.448098</td><td align="center" valign="middle" >74</td><td align="center" valign="middle" >9.4250706</td><td align="center" valign="middle" >99</td><td align="center" valign="middle" >9.4144583</td></tr><tr><td align="center" valign="middle" >25</td><td align="center" valign="middle" >9.5239531</td><td align="center" valign="middle" >50</td><td align="center" valign="middle" >9.446675</td><td align="center" valign="middle" >75</td><td align="center" valign="middle" >9.4244978</td><td align="center" valign="middle" >100</td><td align="center" valign="middle" >9.4141513</td></tr></tbody></table></table-wrap></sec></sec><sec id="s4"><title>4. Conclusions</title><p>In the present study, we have developed a nonhomogeneous stochastic model for predicting the Expected Path Length (EPL) of a computer network system with a given set of vulnerabilities at time “t”.</p><p>Knowing EPL as a function of time is extremely important in developing defending strategies for not being exploited. Such strategies will reduce the likelihood of the computer network system being hacked.</p><p>As we observe the behavior of the EPL over the time, it is possible to identify the time ranges where EPL reached a minimum. Small EPL implies higher chance for a hacker to be successful. In other words, a computer network system is more vulnerable to be exploited on the days where the EPL is the smallest. On such time “t”, vulnerabilities and the system are hence more susceptible to be hacked. The same scenario from an attacker’s point of view can be explained. That is, on the days where EPL is at its smallest, the likelihood of making a successful attack attempt is higher. Therefore, an attacker (hacker), who identifies the set of vulnerabilities in a given computer system would put more attempt on exploiting the system on such date where the EPL is at its smallest. This means that we can use this method as a prediction method of attacking (hacking) time.</p><p>By knowing this time for any computer network system, security engineers or IT architects can take the necessary actions in advance to protect their computer system.</p><p>Finally, we have developed our methodology based on a typical computer network system that exists in a real world situation with given vulnerabilities that identifies the EPL and actual time that the subject computer system could be exploited. Thus, industry can apply the developed methodology in their own computer network system with a given (known) vulnerabilities to predict the EPL and most probable time of being exploited.</p></sec><sec id="s5"><title>Cite this paper</title><p>Kaluarachchi, P.K., Tsokos, C.P. and Rajasooriya, S.M. (2018) Non-Homogeneous Stochastic Model for Cyber Security Predictions. Journal of Information Security, 9, 12-24. https://doi.org/10.4236/jis.2018.91002</p></sec></body><back><ref-list><title>References</title><ref id="scirp.80734-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">Kaluarachchi, P.K., Tsokos, C.P. and Rajasooriya, S.M. (2016) Cybersecurity: A Statistical Predictive Model for the Expected Path Length. Journal of information Security, 7, 112-128. https://doi.org/10.4236/jis.2016.73008</mixed-citation></ref><ref id="scirp.80734-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">Rajasooriya, S.M., Tsokos, C.P. and Kaluarachchi, P.K. (2016) Stochastic Modelling of Vulnerability Life Cycle and Security Risk Evaluation. Journal of information Security, 7, 269-279. https://doi.org/10.4236/jis.2016.74022</mixed-citation></ref><ref id="scirp.80734-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">Rajasooriya, S.M., Tsokos, C.P. and Kaluarachchi, P.K. (2017) Cybersecurity: Nonlinear Stochastic models for Predicting the Exploitability. Journal of information Security, 8, 125-140. https://doi.org/10.4236/jis.2017.82009</mixed-citation></ref><ref id="scirp.80734-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">2016 U.S Government Cybersecurity Report.  
https://cdn2.hubspot.net/hubfs/533449/SecurityScorecard_2016_Govt_Cybersecurity_Report.pdf</mixed-citation></ref><ref id="scirp.80734-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">Symantec, Internet Security Threat Report 2016-Volume 21.  
https://www.symantec.com/content/dam/symantec/docs/reports/istr-21-2016-en.pdf</mixed-citation></ref><ref id="scirp.80734-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">NVD, National Vulnerability Database. http://nvd.nist.gov/</mixed-citation></ref><ref id="scirp.80734-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Kijsanayothin, P. (2010) Network Security Modeling with Intelligent and Complexity Analysis. Ph.D. Dissertation, Texas Tech University, Lubbock, Texas, U.S.</mixed-citation></ref><ref id="scirp.80734-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">Schiffman, M. Common Vulnerability Scoring System (CVSS).  
http://www.first.org/cvss/</mixed-citation></ref><ref id="scirp.80734-ref9"><label>9</label><mixed-citation publication-type="other" xlink:type="simple">CVE Details. http://www.cvedetails.com/</mixed-citation></ref><ref id="scirp.80734-ref10"><label>10</label><mixed-citation publication-type="other" xlink:type="simple">Frei, S. (2009) Security Econometrics: The Dynamics of (IN) Security, Ph.D. Dissertation at ETH Zurich.</mixed-citation></ref><ref id="scirp.80734-ref11"><label>11</label><mixed-citation publication-type="other" xlink:type="simple">Joh, H. and Malaiya, Y.K. (2010) A Framework for Software Security Risk Evaluation Using the Vulnerability Lifecycle and CVSS Metrics, Proc. International Workshop on Risk and Trust in Extended Enterprises, November 2010, 430-434.</mixed-citation></ref><ref id="scirp.80734-ref12"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H., Malaiya, Y.K. and Ray, I. (2007) Measuring, Analyzing and Predicting Security Vulnerabilities in Software Systems. Computers and Security Journal, 26, 219-228. https://doi.org/10.1016/j.cose.2006.10.002</mixed-citation></ref><ref id="scirp.80734-ref13"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H. and Malaiya, Y.K. (2008) Application of Vulnerability Discovery Models to Major Operating Systems. IEEE Transactions on Reliability, 57, 14-22.  
https://doi.org/10.1109/TR.2008.916872</mixed-citation></ref><ref id="scirp.80734-ref14"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Alhazmi, O.H. and Malaiya, Y.K. (2005) Modeling the Vulnerability Discovery Process. Proceedings of 16th International Symposium on Software Reliability Engineering, Chicago, 8-11 November 2005, 129-138.  
https://doi.org/10.1109/ISSRE.2005.30</mixed-citation></ref><ref id="scirp.80734-ref15"><label>15</label><mixed-citation publication-type="other" xlink:type="simple">Lawler, G.F. (2006) Introduction to Stochastic processes. 2nd Edition, Chapman and Hall/CRC Taylor and Francis Group, London, New York.</mixed-citation></ref><ref id="scirp.80734-ref16"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Noel, S., Jacobs, M., Kalapa, P. and Jajodia, S. (2005) Multiple Coordinated Views for Network Attack Graphs. Proceedings of the IEEE Workshops on Visualization for Computer Security, Minneapolis, October 2005, 99-106.</mixed-citation></ref><ref id="scirp.80734-ref17"><label>17</label><mixed-citation publication-type="book" xlink:type="simple">Mehta, V., Bartzis, C., Zhu, H., Clarke, E.M. and Wing, J.M. (2006) Ranking Attack Graphs. In: Zamboni, D. and Krugel, C., Eds., Recent Advances in Intrusion Detection, Volume 4219 of Lecture Notes in Computer Science, Springer, Berlin, 127-144.</mixed-citation></ref><ref id="scirp.80734-ref18"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Abraham, S. and Nair, S. (2014) Cyber Security Analytics: A Stochastic Model for Security Quantification using Absorbing Markov Chains. Journal of Communications, 9, 899-907. https://doi.org/10.12720/jcm.9.12.899-907</mixed-citation></ref><ref id="scirp.80734-ref19"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Jajodia, S. and Noel, S. (2005) Advanced Cyber Attack Modeling, Analysis, and Visualization. 14th USENIX Security Symposium, Technical Report 2010, George Mason University, Fairfax.</mixed-citation></ref><ref id="scirp.80734-ref20"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Wang, L., Singhal, A. and Jajodia, S. (2007) Measuring Overall Security of Network Configurations using Attack Graphs. Data and Applications Security, 21, 98-112.  
https://doi.org/10.1007/978-3-540-73538-0_9</mixed-citation></ref><ref id="scirp.80734-ref21"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Wang, L., Islam, T., Long, T., Singhal, A. and Jajodia, S. (2008) An Attack Graph-Based Probabilistic Security Metric. DAS 2008, LNCS 5094, 283-296.</mixed-citation></ref></ref-list></back></article>