Doorgaan naar hoofdnavigatie Doorgaan naar zoeken Ga verder naar hoofdinhoud

How CVSS is DOSsing your patching policy (and wasting your money).

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageProfessioneel

3933 Downloads (Pure)

Samenvatting

CVSS score is widely used as the standard-de-facto risk metric for vulnerabilities, to the point that the US Government itself encourages organizations in using it to prioritize vulnerability patching. We tackle this approach by testing the CVSS score in terms of its efficacy as a "risk score" and "prioritization metric." We test the CVSS against real attack data and as a result, we show that the overall picture is not satisfactory: the (lower-bound) over-investment by using CVSS to choose what vulnerabilities to patch can as high as 300% of an optimal one. We extend the analysis making sure to obtain statistically significant results. However, we present our results at a practical level, focusing on the question: "does it make sense for you to use CVSS to prioritize your vulnerabilities?"
Originele taal-2Engels
TitelBlackHat USA 2013
Aantal pagina's24
StatusGepubliceerd - 2013
Extern gepubliceerdJa
Evenementblackhat USA 2013, 27 July-1 August 2013, Las Vegas, USA - Las Vegas, Verenigde Staten van Amerika
Duur: 27 jul. 20131 aug. 2013
https://www.blackhat.com/us-13/briefings.html#Allodi

Congres

Congresblackhat USA 2013, 27 July-1 August 2013, Las Vegas, USA
Verkorte titelBlackhat2013
Land/RegioVerenigde Staten van Amerika
StadLas Vegas
Periode27/07/131/08/13
Internet adres

Vingerafdruk

Duik in de onderzoeksthema's van 'How CVSS is DOSsing your patching policy (and wasting your money).'. Samen vormen ze een unieke vingerafdruk.

Citeer dit