Improving VRSS-based vulnerability prioritization using analytic hierarchy process

Improving VRSS-based vulnerability prioritization using analytic hierarchy process
复制标题

使用层次分析过程改进基于 VRSS 的漏洞优先级排序

DOI:
10.1016/j.jss.2012.03.057
复制
发表时间:
2012-08
影响因子:
3.5
通讯作者:
Kong,Ying
Kong,Ying
中科院分区:
计算机科学2区
文献类型:
--
作者:
Liu,Qixu;Zhang,Yuqing;Kong,Ying

文献摘要

参考文献

被引文献

相似文献

在计算机系统中发现的漏洞数量呈爆炸式增长。因此,系统管理员的一个关键问题是要优先考虑哪些漏洞。在组织中对脆弱性进行优先排序的必要性已得到广泛认可。漏洞评估系统的重要作用在于尽可能地将漏洞分离开来。评估脆弱性的严重程度主要有两种方法:定性方法和定量方法。本文首先描述了脆弱性评估方法的设计空间,并讨论了定义良好的评估框架的措施。我们分析了11,395个CVE漏洞,揭示了当前三种漏洞评估系统(X-Force、CVSS和VRSS)之间的差异。我们发现,漏洞并没有尽可能地相互分离。为了增加结果的多样性,我们首先在VRSS的基础上,利用层次分析法对漏洞类型进行优先级排序。我们定量表征了漏洞类型,并将该方法应用于11,395个CVE漏洞集。结果表明,利用漏洞类型可以提高定量评分的质量。
The number of vulnerabilities discovered in computer systems has increased explosively. Thus, a key question for system administrators is which vulnerabilities to prioritize. The need for vulnerability prioritization in organizations is widely recognized. The significant role of the vulnerability evaluation system is to separate vulnerabilities from each other as far as possible. There are two major methods to assess the severity of vulnerabilities: qualitative and quantitative methods. In this paper, we first describe the design space of vulnerability evaluation methodology and discuss the measures of well-defined evaluation framework. We analyze 11,395 CVE vulnerabilities to expose the differences among three current vulnerability evaluation systems (X-Force, CVSS and VRSS). We find that vulnerabilities are not separated from each other as much as possible. In order to increase the diversity of the results, we firstly enable vulnerability type to prioritize vulnerabilities using analytic hierarchy process on the basis of VRSS. We quantitatively characterize the vulnerability type and apply the method on the set of 11,395 CVE vulnerabilities. The results show that the quality of the quantitative scores can be improved with the help of vulnerability type.
DOI: 10.1049/iet-ifs:20060055
发表时间: 2007-09
期刊: IET Inf. Secur.
影响因子: --
作者:
P. Mell;K. Scarfone
通讯作者: P. Mell;K. Scarfone
DOI: 10.1016/j.csi.2004.09.002
发表时间: 2005-07
期刊: Comput. Stand. Interfaces
影响因子: --
作者:
J. L. Salmeron;I. Herrero
通讯作者: J. L. Salmeron;I. Herrero
DOI: 10.1109/esem.2009.5315969
发表时间: 2009-10
期刊: 2009 3rd International Symposium on Empirical Software Engineering and Measurement
影响因子: --
作者:
G. Vache
通讯作者: G. Vache
DOI: 10.1109/iccit.2008.250
发表时间: 2008-11
期刊: 2008 Third International Conference on Convergence and Hybrid Information Technology
影响因子: --
作者:
Kang-San Kim;Jung-Min Kang;DoHoon Lee
通讯作者: Kang-San Kim;Jung-Min Kang;DoHoon Lee
DOI: 10.1007/978-3-540-70567-3_22
发表时间: 2008-07
期刊: --
影响因子: --
作者:
Lingyu Wang;T. Islam;Tao Long;A. Singhal;S. Jajodia
通讯作者: Lingyu Wang;T. Islam;Tao Long;A. Singhal;S. Jajodia