Mason Vulnerability Scoring Framework: A Customizable Framework for Scoring Common Vulnerabilities and Weaknesses

Ibifubara Iganibo,Massimiliano Albanese, Kaan Turkmen, Thomas Campbell,Marc Mosko

SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY(2022)

引用 2|浏览5
暂无评分
摘要
One of the first lines of defense against cyberattacks is to understand and evaluate the weaknesses and vulnerabilities that a system exposes to malicious users. To address this need, several scoring systems have been developed, providing security analysts and practitioners with a means of quantifying the severity of common weaknesses and vulnerabilities found in software. However, these scoring systems rely on predefined notions of risk, use fixed equations to compute numerical scores, and do not provide users with the flexibility to fine-tune such equations or factor in new variables altogether. Furthermore, official scores and rankings are updated infrequently, making them less valuable in a rapidly evolving cybersecurity landscape. In this paper, we present the Mason Vulnerability Scoring Framework, a comprehensive and customizable framework for scoring vulnerabilities and ranking common weaknesses that gives users significant control over the scoring and ranking process.
更多
查看译文
关键词
Vulnerability Analysis, Security Metrics, Software Weaknesses
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要