DocumentCode
3143564
Title
Aggregating CVSS Base Scores for Semantics-Rich Network Security Metrics
Author
Pengsu Cheng ; Lingyu Wang ; Jajodia, Sushil ; Singhal, Achintya
Author_Institution
Concordia Inst. for Inf. Syst. Eng., Concordia Univ., Montreal, QC, Canada
fYear
2012
fDate
8-11 Oct. 2012
Firstpage
31
Lastpage
40
Abstract
A network security metric is desirable in evaluating the effectiveness of security solutions in distributed systems. Aggregating CVSS scores of individual vulnerabilities provides a practical approach to network security metric. However, existing approaches to aggregating CVSS scores usually cause useful semantics of individual scores to be lost in the aggregated result. In this paper, we address this issue through two novel approaches. First, instead of taking each base score as an input, our approach drills down to the underlying base metric level where dependency relationships have well-defined semantics. Second, our approach interprets and aggregates the base metrics from three different aspects in order to preserve corresponding semantics of the individual scores. Finally, we confirm the advantages of our approaches through simulation.
Keywords
computer network security; CVSS base score aggregation; common vulnerability scoring system; dependency relationships; individual score semantics; network vulnerabilities; security solutions effectiveness evaluation; semantics-rich network security metrics; Authentication; Equations; Mathematical model; Measurement; Semantics; Vectors;
fLanguage
English
Publisher
ieee
Conference_Titel
Reliable Distributed Systems (SRDS), 2012 IEEE 31st Symposium on
Conference_Location
Irvine, CA
ISSN
1060-9857
Print_ISBN
978-1-4673-2397-0
Type
conf
DOI
10.1109/SRDS.2012.4
Filename
6424837
Link To Document