稳健性
计算机科学
软件安全保证
脆弱性(计算)
安全编码
背景(考古学)
脆弱性评估
漏洞管理
计算机安全
软件
安全信息和事件管理
信息安全
风险分析(工程)
保安服务
云安全计算
业务
云计算
心理学
古生物学
心理弹性
心理治疗师
生物
程序设计语言
操作系统
作者
Joe Samuel,Khalil Aalab,Jason Jaskolka
出处
期刊:Trust, Security And Privacy In Computing And Communications
日期:2020-12-01
被引量:3
标识
DOI:10.1109/trustcom50675.2020.00067
摘要
Over the years, a number of vulnerability scoring frameworks have been proposed to characterize the severity of known vulnerabilities in software-dependent systems. These frameworks provide security metrics to support decision-making in system development and security evaluation and assurance activities. When used in this context, it is imperative that these security metrics be sound, meaning that they can be consistently measured in a reproducible, objective, and unbiased fashion while providing contextually relevant, actionable information for decision makers. In this paper, we evaluate the soundness of the security metrics obtained via several vulnerability scoring frameworks. The evaluation is based on the Method for Designing Sound Security Metrics (MDSSM). We also present several recommendations to improve vulnerability scoring frameworks to yield more sound security metrics to support the development of secure software-dependent systems.
科研通智能强力驱动
Strongly Powered by AbleSci AI