The Common Vulnerability Scoring System (CVSS) and its Applicability to Federal Agency Systems

The Common Vulnerability Scoring System (CVSS) and its Applicability to Federal Agency Systems
复制标题

通用漏洞评分系统 (CVSS) 及其对联邦机构系统的适用性

DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Sasha Romanosky
Sasha Romanosky
中科院分区:
--
文献类型:
--
作者:
P. Mell;K. Scarfone;Sasha Romanosky

文献摘要

被引文献

相似文献

通用漏洞评分系统(CVSS)提供了一个开放的框架,用于传达IT漏洞的特征和影响。国家漏洞数据库(NVD)为公开已知的漏洞提供特定的CVSS分数。联邦机构可以将联邦信息处理标准(FIPS)199安全类别与NVD CVSS分数一起使用,以获得针对每个机构环境量身定制的影响分数。CVSS由三个组组成:基本组、时态组和环境组。每个组产生一个从0.0到10.0的数值分数,以及一个向量,一个反映用于导出分数的值的压缩文本表示。“基本”组表示漏洞的内在特性。“时间”组反映随时间变化的漏洞特征。环境组表示任何用户环境所特有的漏洞特征。CVSS使IT经理、漏洞公告提供商、安全供应商、应用程序供应商和研究人员都能通过采用这种通用的IT漏洞评分语言而受益。
The Common Vulnerability Scoring System (CVSS) provides an open framework for communicating the characteristics and impacts of IT vulnerabilities. The National Vulnerability Database (NVD) provides specific CVSS scores for publicly known vulnerabilities. Federal agencies can use the Federal Information Processing Standards (FIPS) 199 security categories with the NVD CVSS scores to obtain impact scores that are tailored to each agency’s environment. CVSS consists of three groups: Base, Temporal and Environmental. Each group produces a numeric score ranging from 0.0 to 10.0, and a vector, a compressed textual representation that reflects the values used to derive the score. The Base group represents the intrinsic qualities of a vulnerability. The Temporal group reflects the characteristics of a vulnerability that change over time. The Environmental group represents the characteristics of a vulnerability that are unique to any user’s environment. CVSS enables IT managers, vulnerability bulletin providers, security vendors, application vendors and researchers to all benefit by adopting this common language of scoring IT vulnerabilities.