Title :
Aggregating CVSS Base Scores for Semantics-Rich Network Security Metrics
Author :
Pengsu Cheng ; Lingyu Wang ; Jajodia, Sushil ; Singhal, Achintya
Author_Institution :
Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
Abstract :
A network security metric is desirable in evaluating the effectiveness of security solutions in distributed systems. Aggregating CVSS scores of individual vulnerabilities provides a practical approach to network security metric. However, existing approaches to aggregating CVSS scores usually cause useful semantics of individual scores to be lost in the aggregated result. In this paper, we address this issue through two novel approaches. First, instead of taking each base score as an input, our approach drills down to the underlying base metric level where dependency relationships have well-defined semantics. Second, our approach interprets and aggregates the base metrics from three different aspects in order to preserve corresponding semantics of the individual scores. Finally, we confirm the advantages of our approaches through simulation.
Keywords :
computer network security; CVSS base score aggregation; common vulnerability scoring system; dependency relationships; individual score semantics; network vulnerabilities; security solutions effectiveness evaluation; semantics-rich network security metrics; Authentication; Equations; Mathematical model; Measurement; Semantics; Vectors;
Conference_Titel :
Reliable Distributed Systems (SRDS), 2012 IEEE 31st Symposium on
Conference_Location :
Irvine, CA
Print_ISBN :
978-1-4673-2397-0
DOI :
10.1109/SRDS.2012.4