The (un)reliability of NVD vulnerable versions data: an empirical experiment on Google Chrome vulnerabilities

The (un)reliability of NVD vulnerable versions data: an empirical experiment on Google Chrome vulnerabilities
复制标题

NVD 漏洞版本数据的(不)可靠性:Google Chrome 漏洞的实证实验

DOI:
10.1145/2484313.2484377
复制
发表时间:
2013
期刊:
Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
F. Massacci
F. Massacci
中科院分区:
--
文献类型:
--
作者:
Viet Hung Nguyen;F. Massacci

文献摘要

被引文献

相似文献

NVD是研究人员用于对漏洞数据集进行实证研究的最受欢迎的数据库之一。我们最近对NVD报告的Chrome漏洞数据进行了分析,发现数据中存在一个异常现象,即几乎所有漏洞都源于第一个版本。这启发了我们的实验来验证NVD脆弱版本数据的可靠性。在这个实验中,我们验证了每个版本的Chrome,NVD声称脆弱的实际上是脆弱的。实验揭示了Chrome的漏洞数据中的几个错误。此外,我们还分析了这些错误如何影响基础脆弱性实证研究的结论。结果表明,由于数据误差的影响,可能会得出不同的结论。
NVD is one of the most popular databases used by researchers to conduct empirical research on data sets of vulnerabilities. Our recent analysis on Chrome vulnerability data reported by NVD has revealed an abnormally phenomenon in the data where almost vulnerabilities were originated from the first versions. This inspires our experiment to validate the reliability of the NVD vulnerable version data. In this experiment, we verify for each version of Chrome that NVD claims vulnerable is actually vulnerable. The experiment revealed several errors in the vulnerability data of Chrome. Furthermore, we have also analyzed how these errors might impact the conclusions of an empirical study on foundational vulnerability. Our results show that different conclusions could be obtained due to the data errors.