首页> 外文期刊>Computers & Security >Time between vulnerability disclosures: A measure of software product vulnerability
【24h】

Time between vulnerability disclosures: A measure of software product vulnerability

机译:漏洞披露间隔时间:一种衡量软件产品漏洞的方法

获取原文
获取原文并翻译 | 示例

摘要

Time between vulnerability disclosure (TBVD) for individual analysts is proposed as a meaningful measure of the likelihood of finding a zero-day vulnerability within a given timeframe. Based on publicly available data, probabilistic estimates of the TBVD of various software products are provided. Sixty-nine thousand six hundred forty-six vulnerabilities from the National Vulnerability Database (NVD) and the SecurityFocus Vulnerability Database were harvested, integrated and categorized according to the analysts responsible for their disclosure as well as by the affected software products. Probability distributions were fitted to the TBVD per analyst and product. Among competing distributions, the Gamma distribution demonstrated the best fit, with the shape parameter, k, similar for most products and analysts, while the scale parameter, e, differed significantly. For forecasting, autoregressive models of the first order were fitted to the TBVD time series for various products. Evaluation demonstrated that forecasting of TBVD on a per product basis was feasible. Products were also characterized by their relative susceptibility to vulnerabilities with impact on confidentiality, integrity and availability respectively. The differences in TBVD between products is significant, e.g. spanning differences of over 500% among the 20 most common software products in our data. Differences are further accentuated by the differing impact, so that, e.g., the mean working time between disclosure of vulnerabilities with a complete impact on integrity (as defined by the Common Vulnerability Scoring System) for Linux (110 days) exceeds that of Windows 7 (6 days) by over 18 times.
机译:提出了针对各个分析师的漏洞披露间隔时间(TBVD),作为在给定时间范围内发现零日漏洞的可能性的一种有意义的度量。基于公开可用的数据,提供了各种软件产品的TBVD的概率估计。根据负责披露这些漏洞的分析师以及受影响的软件产品,对国家漏洞数据库(NVD)和SecurityFocus漏洞数据库中的6.694.6万个漏洞进行了收集,集成和分类。每个分析人员和产品的TBVD拟合概率分布。在竞争性发行版中,Gamma发行版显示出最佳拟合,形状参数k对于大多数产品和分析师而言都相似,而比例参数e则存在显着差异。为了进行预测,将一阶自回归模型拟合到各种产品的TBVD时间序列。评估表明,按产品预测TBVD是可行的。产品的特征还在于它们相对易受漏洞影响,分别影响机密性,完整性和可用性。产品之间的TBVD差异很大,例如我们数据中20种最常见的软件产品之间的差异超过500%。不同的影响会进一步加剧差异,因此,例如,Linux披露漏洞(对通用漏洞评分系统所定义)具有完整影响(由通用漏洞评分系统定义)的平均间隔(110天)超过了Windows 7( 6天)超过18次。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号