首页> 外文会议>International Symposium on Computing and Networking >The Effect of Common Vulnerability Scoring System Metrics on Vulnerability Exploit Delay
【24h】

The Effect of Common Vulnerability Scoring System Metrics on Vulnerability Exploit Delay

机译:常见漏洞评分系统指标对漏洞利用延迟的影响

获取原文

摘要

Modern system administrators need to monitor disclosed software vulnerabilities and address applicable vulnerabilities via patching, reconfiguration and other measures. In 2017, over 14,000 new vulnerabilities were disclosed, so, a key question for administrators is which vulnerabilities to prioritise. The Common Vulnerability Scoring System (CVSS) is often used to decide which vulnerabilities pose the greatest risk and hence inform patching policy. A CVSS score is indicative of a vulnerability severity, but it doesn't predict the time to exploit for a vulnerability. A prediction of exploit delay would greatly assist vendors in prioritising their patch releases and system administrators in prioritising the installation of these patches. In this paper, we study the effect of CVSS metrics on the time until a proof of concept exploit is developed. We use the National Vulnerability Database (NVD) and the Exploit Database, which represent two of the largest listings of vulnerabilities and exploit data, to show how CVSS metrics can provide better insight into exploit delay. We also investigate the time lag associated with populating CVSS metrics and find that the median delay has increased rapidly from a single day prior to 2017 to 19 days in 2018. This is an alarming trend, given the rapid decline in median vulnerability exploit time from 296 days in 2005 to six days in 2018.
机译:现代系统管理员需要通过修补,重新配置和其他措施监控披露的软件漏洞和解决适用的漏洞。 2017年,披露了超过14,000个新的漏洞,因此,管理员的关键问题是哪种漏洞优先考虑。常见的漏洞评分系统(CVSS)通常用于决定哪种漏洞构成了最大的风险,因此通知修补策略。 CVSS分数表示漏洞严重性,但它不会预测利用漏洞的时间。利用延迟的预测将极大地帮助供应商在优先顺序执行这些修补程序的安装时优先考虑其补丁发布和系统管理员。在本文中,我们研究了CVSS指标对概念开发证据的时间的影响。我们使用国家漏洞数据库(NVD)和Exproit数据库,它代表了两个最大的漏洞列表和利用数据,以展示CVSS指标如何能够更好地深入了解利用延迟。我们还调查与填充CVSSS指标相关的时间滞后,并发现2017年之前的一天中位数延迟迅速增加至2018年。这是一个令人震惊的趋势,鉴于296的中位漏洞利用时间迅速下降2018年2005年的日子到六天。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号