The effect of security education and expertise on security assessments: the case of software vulnerabilities

L. Allodi, M. Cremonini, Fabio Massacci, W. Shim

Research output: Contribution to conferencePaperAcademic

33 Downloads (Pure)

Abstract

In spite of the growing importance of software security and the industry demand for more cyber security expertise in the workforce, the effect of security education and experience on the ability to assess complex software security problems has only been recently investigated. As proxy for the full range of software security skills, we considered the problem of assessing the severity of software vulnerabilities by means of a structured analysis methodology widely used in industry (i.e. the Common Vulnerability Scoring System (\CVSS) v3), and designed a study to compare how accurately individuals with background in information technology but different professional experience and education in cyber security are able to assess the severity of software vulnerabilities. Our results provide some structural insights into the complex relationship between education or experience of assessors and the quality of their assessments. In particular we find that individual characteristics matter more than professional experience or formal education; apparently it is the \emph{combination} of skills that one owns (including the actual knowledge of the system under study), rather than the specialization or the years of experience, to influence more the assessment quality. Similarly, we find that the overall advantage given by professional expertise significantly depends on the composition of the individual security skills as well as on the available information.
Original languageEnglish
Publication statusPublished - 1 Aug 2018
Event17th Annual Workshop on the Economics of Information Security (WEIS 2018) - Innsbruck, Austria
Duration: 18 Jun 201819 Jun 2018
Conference number: 17
http://weis2018.econinfosec.org/

Conference

Conference17th Annual Workshop on the Economics of Information Security (WEIS 2018)
Abbreviated titleWEIS 2018
Country/TerritoryAustria
CityInnsbruck
Period18/06/1819/06/18
Internet address

Fingerprint

Dive into the research topics of 'The effect of security education and expertise on security assessments: the case of software vulnerabilities'. Together they form a unique fingerprint.

Cite this