Nowadays, data has become an invaluable asset to entities and companies, and keeping it secure represents a major challenge. Data centers are responsible for storing data provided by software applications. Nevertheless, the number of vulnerabilities has been increasing every day. Managing such vulnerabilities is essential for building a reliable and secure network environment. Releasing patches to fix security flaws in software is a common practice to handle these vulnerabilities. However, prioritization becomes crucial for organizations with an increasing number of vulnerabilities since time and resources to fix them are usually limited. This review intends to present a survey of vulnerability ranking techniques and promote a discussion on how multi-objective optimization could benefit the management of vulnerabilities risk prioritization. The state-of-the-art approaches for risk prioritization were reviewed, intending to develop an effective model for ranking vulnerabilities in data centers. The main contribution of this work is to point out multi-objective optimization as a not commonly explored but promising strategy to prioritize vulnerabilities, enabling better time management and increasing security.
翻译:目前,数据已成为实体和公司的宝贵资产,确保数据安全是一项重大挑战;数据中心负责储存软件应用程序提供的数据;然而,脆弱性的数量每天都在增加;管理这种脆弱性对于建立可靠和安全的网络环境至关重要;释放补丁以弥补软件的安全缺陷是处理这些脆弱性的一种常见做法;然而,由于时间和修复资源通常有限,确定优先事项对于脆弱性日益增多的组织来说至关重要;本审查打算提出脆弱性等级技术调查,促进讨论多目标优化如何有利于脆弱性风险管理的优先化;审查了风险优先化的最新方法,目的是为数据中心的脆弱程度排名制定有效的模式;这项工作的主要贡献是指出多目标优化,将其作为一项通常没有探讨过但有希望的战略,以便确定脆弱性的优先化,从而能够更好地管理时间和加强安全性。