• DocumentCode
    3143564
  • Title

    Aggregating CVSS Base Scores for Semantics-Rich Network Security Metrics

  • Author

    Pengsu Cheng ; Lingyu Wang ; Jajodia, Sushil ; Singhal, Achintya

  • Author_Institution
    Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
  • fYear
    2012
  • fDate
    8-11 Oct. 2012
  • Firstpage
    31
  • Lastpage
    40
  • Abstract
    A network security metric is desirable in evaluating the effectiveness of security solutions in distributed systems. Aggregating CVSS scores of individual vulnerabilities provides a practical approach to network security metric. However, existing approaches to aggregating CVSS scores usually cause useful semantics of individual scores to be lost in the aggregated result. In this paper, we address this issue through two novel approaches. First, instead of taking each base score as an input, our approach drills down to the underlying base metric level where dependency relationships have well-defined semantics. Second, our approach interprets and aggregates the base metrics from three different aspects in order to preserve corresponding semantics of the individual scores. Finally, we confirm the advantages of our approaches through simulation.
  • Keywords
    computer network security; CVSS base score aggregation; common vulnerability scoring system; dependency relationships; individual score semantics; network vulnerabilities; security solutions effectiveness evaluation; semantics-rich network security metrics; Authentication; Equations; Mathematical model; Measurement; Semantics; Vectors;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Reliable Distributed Systems (SRDS), 2012 IEEE 31st Symposium on
  • Conference_Location
    Irvine, CA
  • ISSN
    1060-9857
  • Print_ISBN
    978-1-4673-2397-0
  • Type

    conf

  • DOI
    10.1109/SRDS.2012.4
  • Filename
    6424837