Improving the Common Vulnerability Scoring System

Improving the Common Vulnerability Scoring System
复制标题

DOI:
10.1049/iet-ifs:20060055
复制
发表时间:
2007-09
期刊:
IET Inf. Secur.
影响因子:
--
通讯作者:
P. Mell;K. Scarfone
P. Mell;K. Scarfone
中科院分区:
其他
文献类型:
--
作者:
P. Mell;K. Scarfone

文献摘要

被引文献

相似文献

通用漏洞评分系统是一种对漏洞影响进行评分的新兴标准。本文介绍了对该评分系统的分析结果以及使用该标准对大量漏洞进行评分的实验结果。尽管发现该评分系统是有用的,但它存在多种缺陷,限制了其衡量漏洞影响的能力。这项研究展示了在该标准的后续版本中如何解决这些缺陷,以及这些改变如何与现有的评分工作向后兼容。最后,提出了对修订评分系统的建议,并对实验进行了分析,这些实验展示了修订版将如何解决在该标准现有版本中发现的缺陷。
The Common Vulnerability Scoring System is an emerging standard for scoring the impact of vulnerabilities. The results of an analysis of the scoring system and that of an experiment scoring a large set of vulnerabilities using the standard are presented. Although the scoring system was found to be useful, it contains a variety of deficiencies that limit its ability to measure the impact of vulnerabilities. The study demonstrates how these deficiencies could be addressed in subsequent versions of the standard and how these changes are backwards-compatible with the existing scoring efforts. In conclusion a recommendation for a revised scoring system and an analysis of experiments that demonstrate how the revision would address deficiencies discovered in the existing version of the standard are presented.