My Software has a Vulnerability, should I worry?
نویسندگان
چکیده
(U.S) Rule-based policies to mitigate software risk suggest to use the CVSS score to measure the individual vulnerability risk and act accordingly: an HIGH CVSS score according to the NVD (National (U.S.) Vulnerability Database) is therefore translated into a “Yes”. A key issue is whether such rule is economically sensible, in particular if reported vulnerabilities have been actually exploited in the wild, and whether the risk score do actually match the risk of actual exploitation. We compare the NVD dataset with two additional datasets, the EDB for the white market of vulnerabilities (such as those present in Metasploit), and the EKITS for the exploits traded in the black market. We benchmark them against Symantec’s threat explorer dataset (SYM) of actual exploit in the wild. We analyze the whole spectrum of CVSS submetrics and use these characteristics to perform a case-controlled analysis of CVSS scores (similar to those used to link lung cancer and smoking) to test its reliability as a risk factor for actual exploitation. We conclude that (a) fixing just because a high CVSS score in NVD only yields negligible risk reduction, (b) the additional existence of proof of concepts exploits (e.g. in EDB) may yield some additional but not large risk reduction, (c) fixing in response to presence in black markets yields the equivalent risk reduction of wearing safety belt in cars (you might also die but still. . . ). On the negative side, our study shows that as industry we miss a metric with high specificity (ruling out vulns for which we shouldn’t worry).
منابع مشابه
Vulnerability discovery & software security
This dissertation is the result of my own work and includes nothing which is the outcome of work done in collaboration except where specifically indicated in the text. This dissertation does not exceed the regulation length of 60,000 words, including tables and footnotes, but excluding the bibliography and appendix. Acknowledgements My work has been supported at various times by a Marshall Scho...
متن کاملچگونگی مبارزه با خستگی ناشی از میاستنی گراو (MG)
When stretcher came to unit and I was put in my bed, nursing personnel of surgical ward said to me hello. I had seen their face from yesterday night when they were transferring patients from emergency ward to this unit. In that time, I had the role of emergency ward assistant manager. Today, I am a weak patient that even is unable for smallest movement. Cause of my admission to hospital is mus...
متن کاملA Pragmatic Policy-driven Xss Protection Framework
2011 ii Specially dedicated to my beloved family and to information security researchers and practitioners iii Acknowledgments I would like to heartily thank Dr. Geraint Price, my research supervisor, for his invaluable advice, guidance and understanding throughout the development of the research. In addition, I would love to convey my special thanks to my company, RS2, for sponsoring part of m...
متن کاملComparison of Effectiveness of Acceptance and Commitment-based Therapy with and without Compassion on Worry, Self-Critical and Anger Rumination Nonclinical Depressed Diabetic Patients: A Clinical Trail
Introduction: Due to the prevalence of depression in diabetes and the importance of negative self-referrals (worry and rumination) in the severity of depression, this study aimed to evaluate the comparative effectiveness of acceptance and commitment-based therapy with and without compassion on worry, anger rumination, and Self-Critical Rumination in Non-clinical depressed diabetic Patients. Met...
متن کاملP-66: The Impact of Infertility on Pschological and Social Status of Women in Iran: A Content Analysis Study
s:7477:"Background: To explore the Impact of Infertility on Pschological and Social Status of Women in Iran Materials and Methods: Design A qualitative design, based on the content analysis approach, was employed for data collection and analysis of the experiences of Iranian women on infertility. Qualitative studies are intended to enhance understanding and describe the world of human experienc...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1301.1275 شماره
صفحات -
تاریخ انتشار 2013