TY - JOUR T1 - Prioritizing Vulnerability Remediation by Determining Attacker-Targeted Vulnerabilities JF - Security Privacy, IEEE Y1 - 2009 A1 - Michel Cukier A1 - Panjwani,S. KW - attacker-targeted vulnerabilities KW - intrusion detection KW - malicious connections KW - security of data KW - vulnerability remediation KW - Windows service pack AB - This article attempts to empirically analyze which vulnerabilities attackers tend to target in order to prioritize vulnerability remediation. This analysis focuses on the link between malicious connections and vulnerabilities, where each connection is considered malicious. Attacks requiring multiple connections are counted as multiple attacks. As the number of connections increases, so does the cost of recovering from the intrusion. The authors deployed four honey pots for four months, each running a different Windows service pack with its associated set of vulnerabilities. They then performed three empirical analyses to determine the relationship between the number of malicious connections and the total number of vulnerabilities, the number of malicious connections and the number of the vulnerabilities for different services, and the number of known successful attacks and the number of vulnerabilities for different services. VL - 7 SN - 1540-7993 CP - 1 M3 - 10.1109/MSP.2009.13 ER -