Benchmarking vulnerability scanners: An experiment on SCADA devices and scientific instruments

Malaka El, Emma McMahon, Sagar Samtani, Mark Patton, Hsinchun Chen

Research output: Chapter in Book/Report/Conference proceedingConference contribution

20 Scopus citations

Abstract

Cybersecurity is a critical concern in society today. One common avenue of attack for malicious hackers is exploiting vulnerable websites. It is estimated that there are over one million websites that are attacked daily. Two emerging targets of such attacks are Supervisory Control and Data Acquisition (SCADA) devices and scientific instruments. Vulnerability assessment tools can help provide owners of these devices with the knowledge on how to protect their infrastructure. However, owners face difficulties in identifying which tools are ideal for their assessments. This research aims to benchmark two state-of-The-Art vulnerability assessment tools, Nessus and Burp Suite, in the context of SCADA devices and scientific instruments. We specifically focus on identifying the accuracy, scalability, and vulnerability results of the scans. Results of our study indicate that both tools together can provide a comprehensive assessment of the vulnerabilities in SCADA devices and scientific instruments.

Original languageEnglish (US)
Title of host publication2017 IEEE International Conference on Intelligence and Security Informatics
Subtitle of host publicationSecurity and Big Data, ISI 2017
EditorsLina Zhou, G. Alan Wang, Chunxiao Xing, Bo Luo, Xiaolong Zheng, Hui Zhang
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages83-88
Number of pages6
ISBN (Electronic)9781509067275
DOIs
StatePublished - Aug 8 2017
Event15th IEEE International Conference on Intelligence and Security Informatics, ISI 2017 - Beijing, China
Duration: Jul 22 2017Jul 24 2017

Publication series

Name2017 IEEE International Conference on Intelligence and Security Informatics: Security and Big Data, ISI 2017

Other

Other15th IEEE International Conference on Intelligence and Security Informatics, ISI 2017
Country/TerritoryChina
CityBeijing
Period7/22/177/24/17

Keywords

  • Burp
  • Nessus
  • SCADA
  • benchmark
  • scientific instruments
  • vulnerability assessment tools

ASJC Scopus subject areas

  • Artificial Intelligence
  • Computer Networks and Communications
  • Information Systems
  • Information Systems and Management
  • Safety, Risk, Reliability and Quality

Fingerprint

Dive into the research topics of 'Benchmarking vulnerability scanners: An experiment on SCADA devices and scientific instruments'. Together they form a unique fingerprint.

Cite this