首页> 外文期刊>Computer Communications >VRSS: A new system for rating and scoring vulnerabilities
【24h】

VRSS: A new system for rating and scoring vulnerabilities

机译:VRSS:一种新的漏洞评级和评分系统

获取原文
获取原文并翻译 | 示例

摘要

Vulnerabilities are extremely important for network security. IT management must identify and assess vulnerabilities across many disparate hardware and software platforms to prioritize these vulnerabilities and remediate those that pose the greatest risk. The focus of our research is the comparative analysis of existing vulnerability rating systems, so as to discover their respective advantages and propose a compatible rating framework to unify them. We do the statistic work on vulnerabilities of three famous vulnerability databases (IBM ISS X-Force, Vupen Security and National Vulnerability database) and analyze the distribution of vulnerabilities to expose the differences among different vulnerability rating systems. The statistical results show that the distributions of vulnerabilities are not much consistent with the normal distribution. Taking into account all kinds of existing vulnerability rating systems, we propose VRSS for qualitative rating and quantitative scoring vulnerabilities, which can combine respective advantages of all kinds of vulnerability rating systems. An experimental study of 33,654 vulnerabilities demonstrates that VRSS works well.
机译:漏洞对于网络安全极为重要。 IT管​​理人员必须识别和评估许多不同的硬件和软件平台上的漏洞,以便对这些漏洞进行优先级排序并补救构成最大风险的漏洞。我们研究的重点是对现有漏洞评级系统的比较分析,以便发现它们各自的优点并提出一个兼容的评级框架以统一它们。我们对三个著名漏洞数据库(IBM ISS X-Force,Vupen Security和National Vulnerability数据库)的漏洞进行统计工作,并分析漏洞的分布以揭示不同漏洞评级系统之间的差异。统计结果表明,漏洞的分布与正态分布不太一致。考虑到现有的各种漏洞评级系统,我们提出了VRSS的定性评级和定量评分漏洞,可以结合各种漏洞评级系统各自的优势。对33,654个漏洞的实验研究表明,VRSS效果很好。

著录项

  • 来源
    《Computer Communications》 |2011年第3期|p.264-273|共10页
  • 作者

    Qixu Liu; Yuqing Zhang;

  • 作者单位

    National Computer Network Intrusion Protection Center, CUCAS, Beijing 100049, PR China State Key Laboratory of Information Security, CUCAS, Beijing 100049, PR China;

    National Computer Network Intrusion Protection Center, CUCAS, Beijing 100049, PR China State Key Laboratory of Information Security, CUCAS, Beijing 100049, PR China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    vulnerability; qualitative rating; quantitative scoring;

    机译:脆弱性;定性评级;定量评分;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号