Estimating the assessment difficulty of CVSS environmental metrics : an experiment

L. Allodi, S. Biagioni, B. Crispo, K. Labunets, F. Massacci, W. Santos

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

4 Citaten (Scopus)

Samenvatting

[Context] The CVSS framework provides several dimensions to score vulnerabilities. The environmental metrics allow security analysts to downgrade or upgrade vulnerability scores based on a company’s computing environments and security requirements. [Question] How difficult is for a human assessor to change the CVSS environmental score due to changes in security requirements (let alone technical configurations) for PCI-DSS compliance for networks and systems vulnerabilities of different type? [Results] A controlled experiment with 29 MSc students shows that given a segmented network it is significantly more difficult to apply the CVSS scoring guidelines on security requirements with respect to a flat network layout, both before and after the network has been changed to meet the PCI-DSS security requirements. The network configuration also impact the correctness of vulnerabilities assessment at system level but not at application level. [Contribution] This paper is the first attempt to empirically investigate the guidelines for the CVSS environmental metrics. We discuss theoretical and practical key aspects needed to move forward vulnerability assessments for large scale systems.
Originele taal-2Engels
TitelFuture Data and Security Engineering
Subtitel4th International Conference, FDSE 2017, Ho Chi Minh City, Vietnam, November 29 – December 1, 2017, Proceedings
RedacteurenT.K. Dang, R. Wagner, J. Küng, N. Thoai, M. Takizawa, E.J. Neuhold
Plaats van productieBerlin
UitgeverijSpringer
Pagina's23-39
Aantal pagina's17
ISBN van elektronische versie978-3-319-70004-5
ISBN van geprinte versie978-3-319-70003-8
DOI's
StatusGepubliceerd - 2017

Publicatie series

NaamLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10646 LNCS
ISSN van geprinte versie0302-9743
ISSN van elektronische versie1611-3349

Vingerafdruk Duik in de onderzoeksthema's van 'Estimating the assessment difficulty of CVSS environmental metrics : an experiment'. Samen vormen ze een unieke vingerafdruk.

Citeer dit