Title :
Study on the distribution of CVSS environmental score
Author :
Han Li;Rongrong Xi;Li Zhao
Author_Institution :
National Computer Network Emergency Response, Technical Team/Coordination Center of China, (CNCERT/CC) Beijing, China
fDate :
5/1/2015 12:00:00 AM
Abstract :
This paper focuses on analyzing the distribution of CVSS environmental score. Firstly we extract CVSS base score from the NVD database and calculate their corresponding environmental score by simulating all possible combinations of different environmental metrics, then analyze the distribution of the environmental score. Two conclusions are obtained: first, for any given vulnerability, there exists a mode value among all its possible environmental scores; second, the relationships between the maximum decrease or increase of the environmental score and the base score fits particular functions. Finally we use three vulnerabilities provided by NVD as a case study to verify the conclusions proposed in this paper.
Keywords :
"Security","Databases","Loss measurement","Market research","NIST"
Conference_Titel :
Electronics Information and Emergency Communication (ICEIEC), 2015 5th International Conference on
Print_ISBN :
978-1-4799-7283-8
DOI :
10.1109/ICEIEC.2015.7284502