4.4 Article

Measuring the accuracy of software vulnerability assessments: experiments with students and professionals

期刊

EMPIRICAL SOFTWARE ENGINEERING
卷 25, 期 2, 页码 1063-1094

出版社

SPRINGER
DOI: 10.1007/s10664-019-09797-4

关键词

Software vulnerabilities; Risk assessment; Cybersecurity management; CVSS; Knowledge units; Professionalization

资金

  1. European Union [285223, 830929]
  2. NWO through the SpySpot project [628.001.004]

向作者/读者索取更多资源

Assessing the risks of software vulnerabilities is a key process of software development and security management. This assessment requires to consider multiple factors (technical features, operational environment, involved assets, status of the vulnerability lifecycle, etc.) and may depend from the assessor's knowledge and skills. In this work, we tackle with an important part of this problem by measuring the accuracy of technical vulnerability assessments by assessors with different level and type of knowledge. We report an experiment to compare how accurately students with different technical education and security professionals are able to assess the severity of software vulnerabilities with the Common Vulnerability Scoring System (v3) industry methodology. Our results could be useful for increasing awareness about the intrinsic subtleties of vulnerability risk assessment and possibly better compliance with regulations. With respect to academic education, professional training and human resources selections our work suggests that measuring the effects of knowledge and expertise on the accuracy of software security assessments is feasible albeit not easy.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.4
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据