Estimating the Assessment Difficulty of CVSS Environmental Metrics

An Experiment

Conference Paper (2017)
Author(s)

Luca Allodi (Eindhoven University of Technology)

Silvio Biagioni (Università degli Studi di Trento)

Bruno Crispo (Università degli Studi di Trento)

K. Labunets (TU Delft - Safety and Security Science)

Fabio Massacci (Università degli Studi di Trento)

Wagner Santos (Università degli Studi di Trento)

Safety and Security Science
Copyright
© 2017 Luca Allodi, Silvio Biagioni, Bruno Crispo, K. Labunets, Fabio Massacci, Wagner Santos
DOI related publication
https://doi.org/10.1007/978-3-319-70004-5_2
More Info
expand_more
Publication Year
2017
Language
English
Copyright
© 2017 Luca Allodi, Silvio Biagioni, Bruno Crispo, K. Labunets, Fabio Massacci, Wagner Santos
Safety and Security Science
Pages (from-to)
23-39
ISBN (print)
978-3-319-70003-8
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

[Context] The CVSS framework provides several dimensions to score vulnerabilities. The environmental metrics allow security analysts to downgrade or upgrade vulnerability scores based on a company’s computing environments and security requirements. [Question] How difficult is for a human assessor to change the CVSS environmental score due to changes in security requirements (let alone technical configurations) for PCI-DSS compliance for networks and systems vulnerabilities of different type? [Results] A controlled experiment with 29 MSc students shows that given a segmented network it is significantly more difficult to apply the CVSS scoring guidelines on security requirements with respect to a flat network layout, both before and after the network has been changed to meet the PCI-DSS security requirements. The network configuration also impact the correctness of vulnerabilities assessment at system level but not at application level. [Contribution] This paper is the first attempt to empirically investigate the guidelines for the CVSS environmental metrics. We discuss theoretical and practical key aspects needed to move forward vulnerability assessments for large scale systems.

Files

FDSE_2017_paper_34.pdf
(pdf | 0.637 Mb)
License info not available